# Final Model Privacy Form Under the Gramm-Leach-Bliley Act

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3AE9-27882

## Record

- **Collection:** Federal Register
- **Document type:** Rule
- **Published:** December 1, 2009
- **Citation:** 74 FR 62890

## Text

DEPARTMENT OF THE TREASURY
Office of the Comptroller of the Currency
12 CFR Part 40
[Docket ID OCC-2009-0011]
RIN 1557-AC80
FEDERAL RESERVE SYSTEM
12 CFR Part 216
[Docket No. R-1280]
FEDERAL DEPOSIT INSURANCE CORPORATION
12 CFR Part 332
RIN 3064-AD16
DEPARTMENT OF THE TREASURY
Office of Thrift Supervision
12 CFR Part 573
[Docket ID OTS-2009-0014]
RIN 1550-AC12
NATIONAL CREDIT UNION ADMINISTRATION
12 CFR Part 716
RIN 3133-AC84
FEDERAL TRADE COMMISSION
16 CFR Part 313
[Project No. 034815]
RIN 3084-AA94
COMMODITY FUTURES TRADING COMMISSION
17 CFR Part 160
RIN 3038-AC04
SECURITIES AND EXCHANGE COMMISSION
17 CFR Part 248
[Release Nos. 34-61003, IA-2950, IC-28997; File No. S7-09-07]
RIN 3235-AJO6
Final Model Privacy Form Under the Gramm-Leach-Bliley Act

AGENCIES:

Office of the Comptroller of the Currency, Treasury (OCC); Board of Governors of the Federal Reserve System (Board); Federal Deposit Insurance Corporation (FDIC); Office of Thrift Supervision, Treasury (OTS); National Credit Union Administration (NCUA); Federal Trade Commission (FTC); Commodity Futures Trading Commission (CFTC); and Securities and Exchange Commission (SEC).

ACTION:

Final rule.

SUMMARY:

The OCC, Board, FDIC, OTS, NCUA, FTC, CFTC, and SEC (the “Agencies”) are publishing final amendments to their rules that implement the privacy provisions of Subtitle A of Title V of the Gramm-Leach-Bliley Act (“GLB Act”). These rules require financial institutions to provide initial and annual privacy notices to their customers. Pursuant to Section 728 of the Financial Services Regulatory Relief Act of 2006 (“Regulatory Relief Act” or “Act”), the Agencies are adopting a model privacy form that financial institutions may rely on as a safe harbor to provide disclosures under the privacy rules. In addition, the Agencies other than the SEC are eliminating the safe harbor permitted for notices based on the Sample Clauses currently contained in the privacy rules if the notice is provided after December 31, 2010. Similarly, the SEC is eliminating the guidance associated with the use of notices based on the Sample Clauses in its privacy rule if the notice is provided after December 31, 2010.

DATES:

This rule is effective on December 31, 2009, except for the following amendments, which are effective January 1, 2012:

Instructions 3B, 10B, 17B, 24B, 31B, 38B, 45B, and 52B removing paragraphs (g) to 12 CFR 40.6, 216.6, 332.6, 573.6, and 716.6, 16 CFR 313.6, and 17 CFR 160.6 and 248.6, respectively; and

Instructions 7B, 14B, 21B, 28B, 35B, 42B, 49B, and 55B removing Appendixes B to 12 CFR parts 40, 216, 332, 573, and 716, 16 CFR part 313, and 17 CFR parts 160 and 248, respectively.

FOR FURTHER INFORMATION CONTACT:

OCC:
Stephen Van Meter, Assistant Director, Community and Consumer Law Division, (202) 874-5750; Heidi Thomas, Special Counsel, Legislative and Regulatory Activities Division, (202) 874-5090; or David Nebhut, Director, Policy Analysis Division, (202) 874-5220, Office of the Comptroller of the Currency, 250 E Street, SW., Washington, DC 20219.

Board:
Jeanne Hogarth, Consumer Policies Program Manager, Jelena McWilliams, Attorney, or Ky Tran-Trong, Counsel, Division of Consumer and Community Affairs, (202) 452-3667; Kara Handzlik, Attorney, Legal Division, (202) 452-3852; Board of Governors of the Federal Reserve System, 20th Street and Constitution Avenue, NW., Washington, DC 20551.

FDIC:
Samuel Frumkin, Senior Policy Analyst, Division of Supervision and Consumer Protection, (202) 898-6602; or Kimberly A. Stock, Counsel, (202) 898-3815, Legal Division; Federal Deposit Insurance Corporation, 550 17th Street, NW., Washington, DC 20429.

OTS:
Ekita Mitchell, Consumer Regulations Analyst, (202) 906-6451; or Richard Bennett, Senior Compliance Counsel, Regulations and Legislation Division, (202) 906-7409; 1700 G Street, NW., Washington, DC 20552.

NCUA:
Regina Metz, Staff Attorney, (703) 518-6561, Office of General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.

FTC:
Loretta Garrison, Senior Attorney, and Anthony Rodriguez, Attorney, Division of Privacy and Identity Protection, Bureau of Consumer Protection, (202) 326-2252, Federal Trade Commission, 600 Pennsylvania Avenue, NW., Stop NJ-3158, Washington, DC 20580.

CFTC:
Laura Richards, Deputy General Counsel, (202) 418-5126, or Gail B. Scott, Counsel, Office of General Counsel, (202) 418-5139, Commodity Futures Trading Commission, Three Lafayette Centre, 1155 21st Street, NW., Washington, DC 20581.

SEC:
Paula Jenson, Deputy Chief Counsel, or Brice Prince, Special Counsel, Office of the Chief Counsel, Division of Trading and Markets, (202) 551-5550; or Penelope Saltzman, Assistant Director, Thoreau Bartmann, Senior Counsel, or Daniel Chang, Staff Attorney, Office of Regulatory Policy, Division of Investment Management, (202) 551-6792, Securities and Exchange Commission, 100 F Street, NE., Washington, DC 20549.

SUPPLEMENTARY INFORMATION:

The Agencies are publishing final amendments to each of their rules (which are consistent and comparable) that implement the privacy provisions of the GLB Act: 12 CFR part 40 (OCC); 12 CFR part 216 (Board); 12 CFR part 332 (FDIC); 12 CFR part 573 (OTS); 12 CFR part 716 (NCUA); 16 CFR part 313 (FTC); 17 CFR part 160 (CFTC); and 17 CFR part 248 (SEC) (collectively, the “privacy rule”).
1

1
Because the Agencies' privacy rules generally use consistent section numbering, relevant sections will be cited, for example, as “section __.6” unless otherwise noted.

I. Introduction

A. Statutory Authority and Overview

B. Overview of the Final Model Privacy Form

II. Background

A. The Gramm-Leach-Bliley Act Privacy Notices

B. Development of Proposed Model Privacy Form

C. Overview of Comments Received

D. Quantitative Research

E. Public Comments on the Quantitative Test Data

F. Validation Testing

III. The Final Model Privacy Form

A. Standardization

B. Instructions for Use

C. Format of the Notice

D. Appearance of the Model Privacy Form

E. Optional General Guidance for Easily Readable Type

F. Printing, Color, and Logos

G. Jointly-Provided Notices

H. Use of the Form by Differently-Regulated Entities

I. Page One of the Model Form

J. Page Two of the Model Form

K. Other Issues

IV. The Sample Clauses

V. Effective Date

VI. Final Regulatory Flexibility Analysis

VII. Paperwork Reduction Act

VIII. OCC and OTS Executive Order 12866 Determination

IX. OCC and OTS Executive Order 13132 Determination

X. OCC and OTS Unfunded Mandates Reform Act of 1995 Determination

XI. SEC Cost-Benefit Analysis

XII. SEC Consideration of Burden on Competition

XIII. NCUA: The Treasury And General Government Apropriations Act, 1999-Assessment of Federal Regulations and Policies on Families

XIV. CFTC Cost-Benefit Analysis

I. Introduction

A. Statutory Authority and Overview

The Regulatory Relief Act was enacted on October 13, 2006.
2

Section 728 of the Act directs the Agencies to “jointly develop a model form which may be used, at the option of the financial institution, for the provision of disclosures under [section 503 of the GLB Act].”
3

The Regulatory Relief Act stipulates that the model form shall be a safe harbor for financial institutions that elect to use it. Section 728 further directs that the model form shall:

2
Public Law No. 109-351, 120 Stat. 1966 (2006).

3

Id.,
adding 15 U.S.C. 6803(e).
See also infra
discussion at section II.A. on the GLB Act requirements for financial privacy notices. Section 728 of the Regulatory Relief Act directs the agencies named in Section 504(a)(1) of the GLB Act, 15 U.S.C. 6804(a)(1), to develop a model form. The CFTC, which did not become subject to Title V of the GLB Act until 2000, is not named in that section. The Commodity Exchange Act (“CEA”) was amended in 2000 by the Commodity Futures Modernization Act of 2000 to make the CFTC a “Federal functional regulator” subject to the GLB Act Title V.
See
Section 5g of the CEA, 7 U.S.C. 7b-2. The CFTC interprets Section 728 of the Regulatory Relief Act as applying to it through Section 5g.

(A) Be comprehensible to consumers, with a clear format and design;

(B) provide for clear and conspicuous disclosures;

(C) enable consumers easily to identify the sharing practices of a financial institution and to compare privacy practices among financial institutions; and

(D) be succinct, and use an easily readable type font.

On March 29, 2007, the Agencies published a proposed model privacy form (the “proposed model form”) that financial institutions would be able to use to comply with certain disclosures under the privacy rule.
4

On April 15, 2009, the SEC reopened the comment period on the proposed rulemaking to solicit comment on a research report and test data pertaining to additional consumer testing of the proposed model privacy form.
5

Today, the Agencies are amending the privacy rule to include a model privacy form that institutions may use to provide required disclosures. The final model form is substantially as proposed with changes based on comments we received as well as additional consumer testing.

4

See
Interagency Proposal for Model Privacy Form under the Gramm-Leach-Bliley Act (“Proposed Rule”), 72 FR 14940 (Mar. 29, 2007), available at
http://www.ftc.gov/os/2007/03/CorrectedNeptuneMarsandGenericFormsfrn.pdf.
A Correction Notice was published at 72 FR 16875 (Apr. 5, 2007).

5

See
Interagency Proposal for Model Privacy Form under the Gramm-Leach-Bliley Act, Securities Exchange Act Release No. 59769, Investment Company Act Release No. 28697 (Apr. 15, 2009) [74 FR 17925 (Apr. 20, 2009)].

B. Overview of the Final Model Privacy Form

As explained more fully in the Agencies' Proposed Rule, key elements of the final model form's structure and design, as well as vocabulary, reflect the research findings of the qualitative consumer testing.
6

The Agencies believe that the final model form as revised meets all the requirements of the Act and, based on the qualitative research that led to the development of the proposed model form and the quantitative consumer testing described below, is easier to understand and use than most privacy notices currently being disseminated.

6
The Agencies conducted the consumer research in two phases: the first was qualitative testing or form development; the second was quantitative testing.
See infra
section II.

While the model form provides a legal safe harbor, institutions may continue to use other types of notices that vary from the model form so long as these notices comply with the privacy rule. For example, an institution could continue to use a simplified notice if it does not have affiliates and does not intend to share nonpublic personal information with nonaffiliated third parties outside of the exceptions provided in sections __.14 and __.15.
7

Likewise, while the Agencies are eliminating the Sample Clauses and related safe harbor (or, for the SEC, guidance), institutions may continue to use notices containing these clauses, so long as these notices comply with the privacy rule.
8

7

See
privacy rule, section __.6(c)(5), NCUA section 716.6(e)(5).

8

See infra
section IV.

The following section briefly summarizes the key features of the final model form and the changes to the proposed form. A detailed discussion of the elements of the final model form appears in section III.

1. The Structure

The final model form has two pages, rather than the three pages in the proposed form, and may be printed on a single piece of paper.
9

Together, pages one and two address the legal requirements of applicable Federal financial privacy laws and are designed to increase consumer comprehension. The Agencies are not mandating a specific paper size in the final model form as long as the paper is in portrait orientation and sufficient to accommodate minimum font size, spacing, and content requirements.

9
For ease, the Appendix provides three versions of the final model form: (1) Model form with no opt-out; (2) model form with telephone and Web opt-out only; and (3) model form that includes a mail-in opt-out form. An alternative mail-in form (version 4) may be substituted for the mail-in portion of the model form in version 3. For those institutions that use the model form and need to provide a mail-in opt-out form, the reverse side to that opt-out form must not include any content of the model form.
See
F.4 of the Frequently Asked Questions for the Privacy Regulation, available at
http://www.ftc.gov/privacy/glbact/glb-faq.htm
(Dec. 2001) (staff guidance issued by the Board, FDIC, FTC, OCC, OTS, and NCUA) (stating that a consumer generally should be able to detach a mail-in opt-out form from a privacy notice without removing text from the privacy policy).

2. Page One—Background Information, the Disclosure Table, and Opt-Out Information

Page one of the final model form has five parts: (1) The title; (2) an introductory section called the “key frame” which provides context to help the consumer understand the required disclosures; (3) a disclosure table that describes the types of sharing used by financial institutions consistent with Federal law, which of those types of sharing the institution actually does, and whether the consumer can limit or opt out of any of the institution's sharing; (4) only if needed, a box titled “To limit our sharing” for opt-out information; and (5) the institution's customer service contact information. Where the institution provides a mail-in

opt-out form, that form appears at the bottom of page one.

There are three significant changes on page one of the final model form.
10

First, the “What?” box has been modified to permit institutions to select from a menu of terms the types of information collected and shared (other than Social Security number). Second, information (if needed) about how to limit sharing or opt out follows the disclosure table. If the institution provides a mail-in opt-out form, that form appears at the bottom of page one. Third, the final model form includes at the top of the page in the right-hand corner the date by month and year of the most recent version of the notice. Institutions may include at the bottom of page one a “tagline” (an internal identifier) or barcode for information internal to the company, so long as these do not interfere with the clarity or text of the form.
11

10

See infra
section III.I.

11

See, e.g.,
comment letters of T. Rowe Price Associates, Inc. (May 29, 2007); Wolters Kluwer Financial Services (May 24, 2007).

3. Page Two—Supplemental Information

As in the proposed model form, the second page of the final model form provides additional explanatory information that, in combination with page one, ensures that the notice includes all elements described in the GLB Act as implemented by the privacy rule. There is supplemental information in the form of Frequently Asked Questions (“FAQs”)
12

at the top and definitions below. There are three significant changes to the disclosures on page two of the final form.
13

First, a new FAQ appears at the top of page two that can be used to identify those institutions that jointly provide the notice. Second, the FAQ on the collection of information has been modified to allow institutions to select from a menu of terms. Third, a new box has been provided at the bottom of page two titled “Other important information.” This box can be used in only two ways: (1) to discuss state and/or international privacy law requirements; and (2) to provide an acknowledgment of receipt form.
14

12
Note that a financial institution must insert its name or a common corporate identity as indicated in the two questions in this section each time that “[name of financial institution]” appears. The revised form has eliminated the FAQ “How does [name of financial institution] notify me about its practices.”

13

See infra
section III.J.

14
This use was provided in response to a request by the National Automobile Dealers Ass'n, whose members routinely ask customers to sign an acknowledgment of receipt on a copy of the dealer's privacy notice and retain this record verifying delivery of the notice. Comment letter of the National Automobile Dealers Ass'n (May 29, 2007).

II. Background

A. The Gramm-Leach-Bliley Act Privacy Notices

Subtitle A of title V of the GLB Act, captioned “Disclosure of Nonpublic Personal Information,”
15

requires each financial institution to provide a notice of its privacy policies and practices to its customers who are consumers.
16

In general, the privacy notice must describe a financial institution's policies and practices with respect to disclosing nonpublic personal information about a consumer to both affiliated and nonaffiliated third parties.
17

The notice also must provide a consumer a reasonable opportunity to direct the institution generally not to share nonpublic personal information
18

about the consumer (that is, to “opt out”) with nonaffiliated third parties other than as permitted by the statute (for example, sharing for everyday business purposes, such as processing transactions and maintaining customers' accounts, and in response to properly executed governmental requests).
19

The privacy notice must provide, where applicable under the Fair Credit Reporting Act (“FCRA”), a notice and an opportunity for a consumer to opt out of certain information sharing among affiliates.
20

15
Codified at 15 U.S.C. 6801-6809.

16
15 U.S.C. 6803(a). A “customer” means a consumer who has a “customer relationship” with a financial institution. Privacy rule, section __.3(h), SEC section 248.3(j), CFTC section 160.3(k), NCUA section 716.3(n). A “consumer” is “an individual who obtains, from a financial institution, financial products or services which are to be used primarily for personal, family, or household purposes, and also means the legal representative of such an individual.” 15 U.S.C. 6809(9); privacy rule, section __.3(e), SEC section 248.3(g)(1), CFTC section 160.3(h)(1). Financial institutions are required to provide an initial notice to their customers and a notice annually thereafter for as long as the customer relationship continues. 15 U.S.C. 6803(a); Privacy rule, sections __.4 and __.5. Institutions are also required to provide to their non-customer consumers a notice if the institution discloses nonpublic personal information outside the exceptions in sections __.14 and __.15 before any such disclosure is made. 15 U.S.C. 6802(a); privacy rule, sections __.4.

17
15 U.S.C. 6803(a)-(c).

18
“Nonpublic personal information” is generally defined as personally identifiable financial information provided by a consumer to a financial institution, resulting from any transaction or any service performed for the consumer, or otherwise obtained by the financial institution.
See
15 U.S.C. 6809(4); privacy rule, sections __.3(n) and (o), SEC sections 248.3(t) and (u), CFTC sections 160.3(t) and (u).

19
15 U.S.C. 6802; privacy rule, sections __.14 and __.15.

20
15 U.S.C. 1681a(d)(2)(A)(iii) (FCRA); 15 U.S.C. 6803(c)(4) (GLB Act).

The privacy rule requires a financial institution to provide a privacy notice to its customers no later than when a customer relationship is formed and annually thereafter for as long as the relationship continues. The notice must accurately reflect the institution's information collection and disclosure practices and must include specific information.
21

21

See
sections_.4,_.5, and _.6 of the privacy rule.

The privacy rule does not prescribe any specific format or standardized wording for these notices. Instead, institutions may design their own notices based on their individual practices provided they comply with the law and meet the “clear and conspicuous” standard in the statute and the privacy rule.
22

The Appendix to each privacy rule contains Sample Clauses that institutions may use in privacy notices to satisfy the privacy rule.

22
15 U.S.C. 6802, 6803; privacy rule, section _.3(b), SEC section 248.3(c), CFTC section 160.3(b)(1).

Financial institutions were required to provide privacy notices to their customers by July 1, 2001.
23

Many notices provided to consumers were long and complex. Because the privacy rule allows institutions flexibility in designing their privacy notices, notices have been formatted in various ways and as a result have been difficult to compare, even among financial institutions with identical practices.
24

The Agencies first explored issues related to the complexity of privacy notices in a workshop held in December 2001.
25

23

See, e.g.,
Privacy of Consumer Financial Information, 65 FR 35162 (June 1, 2000). The CFTC was added by Section 5g of the Commodity Exchange Act, 7 U.S.C. 7b-2 (as amended by the Commodity Futures Modernization Act of 2000), on December 21, 2000, and privacy notices were required to be delivered to consumers by March 31, 2002. Privacy of Consumer Financial Information, 66 FR 21236 (Apr. 27, 2001).

24

See
Rulemaking Petition from Public Citizen,
et al.,
at 4 (July 26, 2001) (available at
http://www.ftc.gov/bcp/workshops/glb/comments/nader.pdf)
(“Public Citizen Petition”) (stating that notices were “dense,” “complicated,” and written by those trained in obfuscation rather than to express ideas clearly).

25

See
Get Noticed: Writing Effective Financial Privacy Notices, Interagency Public Workshop (Dec. 4, 2001) (“Get Noticed Workshop”). Workshop transcripts and other supporting documents are available at
http://www.ftc.gov/bcp/workshops/glb/index.html.
The Get Noticed Workshop, discussed in the preamble to the Proposed Rule,
supra
note 4 at n.14, provided a public forum to consider how financial institutions could provide more useful privacy notices to consumers.

On December 30, 2003, the Agencies published an Advance Notice of Proposed Rulemaking to Consider Alternative Forms of Privacy Notices Under the Gramm-Leach-Bliley Act (“ANPR”) to solicit public comment on

a wide range of issues related to improving privacy notices.
26

The ANPR stated that the Agencies expected that consumer testing would be a key component in the development of any specific proposals.
27

26

See
Interagency Proposal to Consider Alternative Forms of Privacy Notices Under the Gramm-Leach-Bliley Act, 68 FR 75164 (Dec. 30, 2003), available at
http://www.ftc.gov/os/2003/12/031223anprfinalglbnotices.pdf.
The Agencies sought, for example, comment on issues associated with the format, elements, and language used in privacy notices that would make the notices more accessible, readable, and useful, and whether to develop a model privacy notice that would be short and simple.

27

Id.
at text following n.5.

During January and February 2004, the Agencies met with a number of interested groups and individuals to discuss the issues raised in the ANPR and subsequently received forty-four comments in response to the ANPR.
28

While commenters expressed a variety of views on the questions posed in the ANPR, many commenters agreed that the Agencies should conduct consumer testing before proposing any alternative privacy notice.

28
Summaries of the outside meetings and public comments to the ANPR are available at
http://www.ftc.gov/privacy/privacyinitiatives/financial_rule_inrp.html.

B. Development of the Proposed Model Privacy Form

Over the years during which GLB Act privacy notices have been delivered to consumers, the Agencies have observed wide variations in these notices. Today, privacy notices vary considerably—not just in format, presentation, language, length, style, or tone—but also in how they inform consumers of their rights to limit certain sharing of personal information. For example, the Agencies have found the following variations in current privacy notices. Some institutions incorporate privacy notices into lengthy terms and conditions statements, making it harder for consumers to find information about the institution's privacy practices, and raising questions about whether such notices comply with the requirement that they be clear and conspicuous. Institutions also use messages in their notices' opening statements about how they value privacy and strive to “protect” personal information, thus providing assurances to consumers that imply their personal information is not shared broadly, while obscuring or directing attention away from the required disclosures of actual information sharing practices. Finally, the Agencies have seen a number of institutions employ the statement in their privacy policy “We do not sell your information to third parties” in a context that raises concerns about misrepresentations.
29

29
In some cases, the Agencies have identified notices that violate the privacy rule. For example, one institution's privacy notice did not include an opt-out form, but provided that consumers could only obtain an opt-out form by visiting a bank office, in violation of sections _.7(h), _.9(a), and _.10(a)(1) of the privacy rule. Another notice provided that consumers could only opt out by writing a letter to the institution, in violation of section _.7(a)(1) of the privacy rule. Offering only these very restrictive methods of obtaining an opt-out form and opting out also is not supported by the examples in the privacy rule.
See
sections _.7(a)(2), _.9(b), and _.10(a)(3) of the privacy rule.

These examples illustrate the need to make disclosure of institutions' information sharing practices and consumer choices more transparent and underscore the Agencies' interest in initiating a joint consumer research project to develop an easy-to-read and understandable model privacy notice for consumers.

In the summer of 2004, six of the Agencies
30

launched a project to fund consumer research (“Notice Project”). Their goals were to identify barriers to consumer understanding of current privacy notices and to develop an alternative privacy notice, or elements of a notice, that consumers could more easily use and understand compared to current notices. The Agencies conducted the consumer research in two sequential phases.
31

30
The six agencies that initially sponsored the Notice Project were the Board, FDIC, FTC, NCUA, OCC, and SEC. The OTS joined the Notice Project for the phase two quantitative testing. Information related to the Notice Project is available at
http://www.ftc.gov/privacy/privacyinitiatives/financial_rule_inrp.html
.

31
The first phase was designed as qualitative testing or form development research. This research involved a series of in-depth individual consumer interviews to develop an alternative privacy notice that would be easier for consumers to use and understand. The second phase was designed as quantitative testing, to test the effectiveness of the alternative privacy notice developed in phase one among a larger number of consumers.

In September 2004, the Agencies selected Kleimann Communication Group, Inc. (“Kleimann”) as their contractor for the phase one form development research. The research objectives of the Notice Project included designing a privacy notice that consumers could understand and use, that facilitated comparison of sharing practices and policies across institutions, and that addressed all relevant legal requirements of the GLB Act and FCRA.

The form development phase culminated in an extensive research report prepared by Kleimann and released by the Agencies in March 2006 (the “Kleimann Report”).
32

The Kleimann Report details the process by which the Agencies and Kleimann developed an alternative privacy notice. The structure, content, ordering of the text information, and title of the proposed model form all reflect the research findings from the qualitative consumer testing.

32

See
Kleimann Communication Group, Inc., Evolution of a Prototype Financial Privacy Notice: A Report on the Form Development Project (Feb. 28, 2006) (“Kleimann Report”). For a copy of the full report, go to
http://www.ftc.gov/privacy/privacyinitiatives/ftcfinalreport060228.pdf
. For the executive summary, go to
http://www.ftc.gov/privacy/privacyinitiatives/FTCFinalReportExecutiveSummary.pdf
.

In October 2006, Congress passed the Regulatory Relief Act, which directed the Agencies to propose a model form based on standards similar to the Notice Project research goals. On March 29, 2007, the Agencies issued for public comment the proposed model form as produced in the form development phase with some minor revisions.

C. Overview of Comments Received

The Agencies collectively received approximately 110 unique comments from a variety of banks, thrifts, credit unions, credit card companies, securities firms, insurance companies, and industry trade associations, as well as from consumer and other advocacy groups, the National Association of Attorneys General (“NAAG”), the National Association of State Insurance Commissioners (“NAIC”), and individual consumers.
33

33
Comments received by all the Agencies are available at
http://www.ftc.gov/privacy/privacyinitiatives/financial_rule_inrp.html
. Many commenters sent copies of the same letter to more than one agency. Some association commenters sent several letters, both individually and jointly with other associations.

A number of institutions expressed support for the model form. Some stated that they are either already using it (submitting copies of their notices) or intend to use it once it is finalized. One industry association conducted an informal poll of its community bank members and found that many are likely to use the model form and that most found the new form more consumer-friendly than the Sample Clauses. These commenters commended the Agencies for proposing simpler language and making the disclosure terms more understandable and accessible to consumers.

Consumer and other advocacy groups, the NAIC, NAAG, and individual consumers generally supported the Agencies' proposal and the clearer language and omission of extraneous information in the proposed model form. These commenters stated that the proposal could be strengthened in certain respects, for example, by making

the default opt-in rather than opt-out and creating a one-stop opt-out repository similar to the National Do Not Call Registry.

There was general support by many commenters for additional consumer research and testing. While some industry commenters provided substitute language or submitted alternate forms of the notice, none submitted other research findings. However, the NAIC submitted a consumer study on notices with research findings that the Agencies did consider.

Most industry commenters, however, objected to several key aspects of the proposal. The most significant areas of concern raised by industry commenters related to: The standardized approach; the format of the proposed model form; the limited examples of types of personal information collected and shared; the disclosure table; incorporation of state law information; and revocation of the Sample Clauses. The thrust of many industry comments was that the proposed form was overly simplistic and not nuanced enough to describe precisely what the various laws permit or to allow accurate descriptions of more complex information sharing policies and practices. One commenter expressed concern that the form would lead to consumer confusion because of inaccurate disclosures on sharing practices and result in high opt-out rates, discouraging use of the form. Many industry commenters expressed concern about liability under state unfair or deceptive practice laws relating to privacy disclosures. At the same time, many institutions urged flexibility to allow inclusion of other information—such as describing the benefits of sharing, or providing marketing messages or privacy tips such as on identity theft and fraud prevention. One institution proposed allowing institutions to pick and choose which elements of the notice to use and still receive a safe harbor.

D. Quantitative Research

Following publication of the model form proposal in March 2007 and subsequent review of the comments, the Agencies revised the proposed model form for further testing.
34

In the fall of 2007, the Agencies turned their attention to developing the research protocol and methodology for conducting the second phase of the research: The quantitative consumer testing. In August 2006, prior to enactment of the Regulatory Relief Act, the Agencies had selected Macro International Inc. (“Macro”) to conduct the quantitative research study.

34

See
Mall Intercept Study of Consumer Understanding of Financial Privacy Notices: Methodological Report, submitted by Macro International Inc. (“Macro Report”), Appendix C, for copies of the test notices. The Macro Report is available at:
http://www.ftc.gov/privacy/privacyinitiatives/Macro-Report-on-Privacy-Notice-Study.pdf
.
See also infra
section III for a discussion about the changes made to the final model form since the Proposed Rule was issued for comment.

In the spring of 2008, Macro conducted a survey of approximately 1,000 consumers using a mall-intercept methodology. The selected participants for the study reflected a range of demographic characteristics for gender, age, and educational level. The testing was conducted in five shopping mall locations—Baltimore, MD; Dallas, TX; Detroit, MI; Los Angeles, CA; and Springfield, MA—over a period of five weeks during March and April 2008.
35

35
Macro provided the test data to the Agencies in the summer of 2008 and its research methodology report in September. The study data and codebook are available at:
http://www.ftc.gov/privacy/privacyinitiatives/Privacy-Notice-Study-Dataset.pdf
and
http://www.ftc.gov/privacy/privacyinitiatives/Privacy-Notice-Study-Codebook.pdf
.

The test objectives were to evaluate the effectiveness of the revised proposed model form
36

developed by Kleimann (“Table Notice”) for comprehension and usability as compared to three other styles or formats of notices. The other notice formats were: (1) The prose version of the prototype table notice also developed and tested by Kleimann (“Prose Notice”); (2) a current version of a common notice used by financial institutions (“Current Notice”); and (3) a notice comprised solely of the Sample Clauses found in the appendix to the privacy rule (“Sample Clause Notice”). Within each format, there were three different notices, each reflecting a different level of sharing. Each level of sharing had a common fictional bank name across the four notice formats: Mars Bank had a low level of sharing; Mercury Bank had a medium level of sharing; and Neptune Bank had the highest level of sharing. Both Mercury and Neptune Banks offered opt-out choices; however, the pattern of sharing was such that after exercising all available opt-outs, Neptune Bank continued to share more broadly than Mercury Bank and Mercury Bank continued to share more than Mars Bank. This design was intentional for the comparison testing.
37

36
The proposed model form was revised based on the comments received, and a version of that revised form was used in the quantitative testing.

37
Study participants were randomly assigned to see one of the four notice formats. Each participant read three privacy notices in the same format and was asked a series of questions, first about one pair of notices, and next about a second pair of notices, with one of the three notices used twice in each round. The order and repetition of the notices were rotated among the participants so that the same notice was not always viewed twice. Participants answered additional questions about the notices and their attitudes on information sharing. The interview sought information about participants' choice of a bank based solely on the notice content; responses to factual questions, such as which of two banks shared more or whether any of the banks offered an opportunity to limit or opt out of sharing; performance of a task, such as determining which bank shared more after exercising all options to limit or opt out of sharing; and responses to questions about their attitudes toward the use and sharing of their information.
See
Macro Report,
supra
note 34, Appendix A.

On December 15, 2008, two expert advisors to the Agencies, Dr. Alan Levy and Dr. Manoj Hastak, submitted a report to the Agencies analyzing the research data provided by Macro (the “Levy-Hastak Report”).
38

The Levy-Hastak Report confirmed the overall effectiveness of the proposed model form (as modified) as against the three alternative notice formats. On April 15, 2009, the SEC published the Levy-Hastak Report, along with the Macro Report and test data, for public comment. The SEC received nine comments.
39

38

See http://www.ftc.gov/privacy/privacyinitiatives/Levy-Hastak-Report.pdf.

39

See http://www.sec.gov/comments/s7-09-07/s70907.shtml.

The Levy-Hastak Report examined two measures on how effectively the notices communicated information: (1) Judgment quality; and (2) perceptual accuracy.
40

According to the Report, judgment quality focused on the extent to which study participants could provide logical, defensible reasons for choosing one bank over the other based solely on the notice. Perceptual accuracy focused on the ability of the participants to recognize accurately the differences between the banks in information collection and sharing practices, in opt-out choices, and in relative sharing after all opt-out choices were exercised.
41

40
Levy-Hastak Report at 7-14.

41

Id.
at 4-5.

The Levy-Hastak Report concluded that, overall, the Table Notice outperformed the other notices.
42

The Table Notice performed particularly well on difficult tasks
43

while the Current Notice performed poorly on all measures. While the Sample Clause Notice performed well on simple tasks,

about equal to the Table and Prose notices, it performed significantly less well than the Table Notice on measures of judgment quality.
44

The Report concluded that the table format is likely a key explanation for the improvement in comprehension demonstrated by the study participants who saw the Table Notice as compared to those who saw the other notice styles—especially for difficult perceptual accuracy tasks.
45

42

Id.
at 16.

43

Id.
at 17. According to the Report, an example of a difficult task was: Participants were asked to assume that they had limited or opted out of all possible sharing for both banks; based on that assumption, respondents were asked whether one bank shared more personal information than the other or whether both banks shared information equally. An example of an easy task was: Using the notice, participants were asked to identify how they could tell the bank that they wanted to limit or opt out of sharing personal information.

44
Levy-Hastak Report at 9-10.

45
Levy-Hastak Report at 17.

While the notice format significantly affected participants' ability to comprehend and compare the notices, the testing showed that participants' general attitudes about the sharing of their personal information were not affected by the notices they saw.
46

Following the two rounds of questions on the content of, and comparison between, the notices, the study participants were asked to rate their attitudes in general toward information sharing, for example, sharing with affiliated banks and with nonaffiliated banks. The results showed that participants' attitudes were about the same across the four notice formats.
47

46

Id.
at 15.

47

Id.
Study participants generally did not like their information being shared with either affiliates or with nonaffiliates.

The Levy-Hastak Report analyzed two specific areas where the Table Notice seemed to perform less well than the other notices. First, the Report described an anomaly with respect to responses to the question [Q. 19/30]: “Which of these two banks gives you the opportunity to limit or to opt out of the sharing of your personal information?”
48

Generally participants identified the bank or banks that provided an opt-out. However, some participants who saw the Table and Prose notices selected Mars Bank, the one that shared the least and offered no opt-out option. Because answering “Mars Bank” was identified as an incorrect answer, the Current and Sample Clause notices out-performed the Table and Prose notices on this question.

48

See id.
at 12-14.

In contrast, the Table and Prose notices out-performed the other two notices on the most difficult task in the test. In this task, participants were asked to assume that they had exercised all possible options to limit or to opt out of sharing and then to identify which bank shared more. Here, the Table and Prose notices significantly out-performed the other notices. More participants who saw the Table and Prose notices correctly gave as their answer the higher sharing bank. This result suggests that participants who saw the Table and Prose notices did understand which bank(s) offered an opportunity to limit or to opt out of their sharing.

In analyzing this discrepancy, the Levy-Hastak Report observed that the simpler question had two different, yet accurate, responses, depending on how participants interpreted the question. Some of the participants might have understood the question to apply at the point of
choosing between
the two bank notices; those participants selected the lower sharing bank. In contrast, other participants might have understood the question to mean: Which bank lets me opt out of sharing personal information once I am doing business with the bank. The second interpretation was the intended meaning of the question. Drs. Levy and Hastak hypothesized that some participants who saw the Table and Prose notices understood the question to have the first meaning, while other participants, particularly those who saw the Sample Clause and Current notices, understood the question to have the second meaning.
49

49
Significantly, unlike the Sample Clause and Current notices, neither the Table nor the Prose notice uses the word “opt-out” in the model form; rather, these forms refer to “limiting sharing.” This word choice was intentional to help consumers understand that some sharing is necessary and that consumers cannot stop all sharing—a concept that consumers who knew the term equated with “opt-out.”
See
Kleimann Report,
supra
note 32, at 101-108. Because the Table and Prose notices did not use the word “opt-out,” participants using these notices did not have that word as a visual “cue” when they were asked the question.

To test this hypothesis, Drs. Levy and Hastak examined the pattern of factual mistakes that participants made when they answered a separate set of questions.
50

There, study participants were asked in Q. 16/27 why they preferred one bank over the other, based solely on the notice. Some participants who selected a bank that shared relatively little information and did not offer an opt-out stated that this bank offered more opportunity to limit or to opt out of sharing than the higher sharing bank, which was labeled a “false opt-out mistake” in the Report. The Report found that participants who saw the Table and Prose notices were on average almost three times as likely to make the false opt-out mistake as those who saw the Current and Sample Clause notices.
51

50
The Report also examined a second mistake: Where participants selected the lower sharing bank when they were asked to identify which bank shared more (labeled a “false sharing mistake”).
See
Levy-Hastak Report at 9. In that case, there was not an unusual pattern in the distribution of responses. Rather, the Report found that the study participants who made this mistake were equally distributed across all four notice styles.
Id.
at 13.

51

Id.

This finding supports the hypothesis that users of the Table and Prose notices who selected the lower sharing bank in response to Q. 19/30 understood the question in its first meaning: They selected a bank that gave them an opportunity to limit or opt out of sharing at the time of
choosing between
the two bank notices. Under that interpretation, these participants could limit sharing by selecting the bank that shared less information. Thus the Levy-Hastak Report's analysis of the false opt-out mistake pattern in Q. 16/27 is consistent with their hypothesis regarding the responses to Q. 19/30. In addition, the Report found that the educational level of the study participants produced a significant effect only on the responses to the opt-out question, with better educated participants more likely to answer the question in the intended manner.
52

This finding is also consistent with the Report hypothesis that participants who saw the Table and Prose notices understood the question in two different, yet equally correct ways, unlike those who saw the Sample Clause and Current notices.

52

Id.
at 13-14.

The Table Notice also seemed to perform less well in a second, unrelated area. Specifically, all the test notices provided only two methods for consumers to opt out of or limit sharing: Use of a toll-free telephone number or access to the opt-out on the institution's Web site. When study participants were asked to identify which contact modes were identified in the notice as ways to limit or opt out of sharing, they correctly identified the two modes more frequently when using the Sample Clause Notice than the Table, Prose, and Current notices.

Noting that this type of question appears to invite skimming the notice to find the answer quickly and easily, the Levy-Hastak Report examined the great variability in notice length and found that the Sample Clause Notice was significantly shorter than any of the other notices. The Levy-Hastak Report observed that the shortness of the Sample Clause Notice may have made it easier for participants to scan the notice and find the answer to this question. The Report opined that notice length likely has an effect on scanability and reading ease.
53

53
Levy-Hastak Report at 14. In addition, the use of check boxes in the design of the opt-out section of the Table and Prose notices (a carry-over from the original mail-in format of the proposed model form) appeared to confuse some participants when they were asked this question. The responses recorded for these two notices reflected a somewhat higher

number of “other” responses, even though all the notices offered the same two options. Macro reported anecdotally that a number of participants who viewed the Table and Prose notices reported “check this box” as one of the methods offered to opt out or limit sharing—a response that was recorded as “other.”

While the Levy-Hastak Report findings confirmed the overall effectiveness of the Table Notice,
54

the Report's analysis prompted the Agencies to consider a further refinement to the proposed model form. The change, discussed in more detail later, was to modify the opt-out section of the model form to place the opt-out information on page one directly following the disclosure table so that all the key information appears on that page.
55

The Agencies considered this change to facilitate quick scanning for important information without sacrificing the model form's performance in other respects. To ensure that locating the opt-out information on page one worked from a usability perspective, the Agencies decided to conduct validation testing which led to separate formats for the telephone and Internet opt-out and for the mail-in opt-out that the Agencies are adopting.

54

Id.
at 17.

55
Some commenters had urged the Agencies to consolidate the model form on two sides of a single piece of paper, and a few suggested that the Agencies consider moving the opt-out to page one.
See, e.g.,
comment letters of Securities Industry and Financial Markets Ass'n (May 29, 2007); World's Foremost Bank (May 25, 2007); World Financial Network National Bank (May 29, 2007); World Financial Capital Bank (May 25, 2007).

E. Public Comments on the Quantitative Test Data

Nine commenters representing insurance, securities, and financial services associations, a bank, and two investment advisers submitted comments in response to the SEC's solicitation for public comments on the quantitative testing. Most of the commenters re-stated their earlier general objections to the proposed model form. These concerns are addressed in section III.

All but one of these commenters made general observations about the quantitative test methodology and the Levy-Hastak Report. Five commenters observed that the test notices were designed for banks and not for insurance companies or securities firms (
i.e.,
broker-dealers, investment companies, or SEC-registered investment advisers), thereby omitting a significant portion of the financial services industry that provide these notices.
56

Two commenters opined that the study participants' demographic characteristics did not reflect those consumers who will receive financial privacy notices.
57

One expressed concern about the demographic diversity in the mall selections and questioned whether there was consistent coding of the open-ended responses.
58

One commented that the testing criteria ruled out non-English speaking participants.
59

56

See
comment letters of American Council of Life Insurers (May 20, 2009), National Ass'n of Mutual Insurance Cos. (May 20, 2009), American Insurance Ass'n (May 20, 2009), Investment Adviser Ass'n (May 20, 2009), The Financial Services Roundtable and BITS (May 20, 2009).

57

See
comment letters of National Ass'n of Mutual Insurance Cos. (May 20, 2009); The Financial Services Roundtable and BITS (May 20, 2009).

58

See
comment letter of The Financial Services Roundtable and BITS (May 20, 2009).

59

See id.
The Agencies used a single form, printed in English, for simplicity in conducting the testing. We recognize that institutions can and do provide notices in a variety of other languages when their customers are non-English speaking. We anticipate that those institutions that use the final model form will continue to provide their notices in other languages to ensure that their non-English speaking customers can read and use the form.
See also
Transcript of Get Noticed Workshop, available at
http://www.ftc.gov/bcp/workshops/glb/GLBtranscripts.pdf,
comments of Irene Etzkorn (recognizing that banks do provide financial privacy notices in languages other than English); comments of Tena Friery (noting that the Privacy Rights Clearinghouse promotes notices and educational materials in other languages and that 80-100 different languages are spoken in Los Angeles alone).

Some of the commenters disagreed with the Levy-Hastak Report's conclusion that the Table Notice outperformed the other notice formats. They opined that the Report's conclusion is flawed because: (1) The Sample Clause Notice did better on simpler tasks than the Table Notice;
60

(2) the anomalies discussed in the Levy-Hastak Report may be due to other explanations;
61

and (3) while the Table Notice's overall performance was better than the other notices, actual performance accuracy was relatively low.
62

Several commented that the overly simplified and inflexible format of the Table Notice is not a true test of consumers' understanding of institutions' actual collection and disclosure practices.
63

In addition, all commenters on the quantitative testing urged retention of the Sample Clauses and related safe harbor.

60

See
comment letters of American Insurance Ass'n (May 20, 2009); National Ass'n of Mutual Insurance Cos. (May 20, 2009). While some commenters find greater virtue in the better performance of the Sample Clause Notice on only the simpler tasks or disagree with the Levy-Hastak Report's analyses, the evidence is compelling that the Table Notice performed better overall across all comprehension and comparison measures.
See
Levy-Hastak Report at 6.

61

See
comment letter of American Council of Life Insurers (May 20, 2009).

62

Id.

63

See, e.g.,
comment letter of The Financial Services Roundtable and BITS (May 20, 2009).

The test notices for the quantitative study were created for fictitious banks, even though the model form can be used by any financial institution subject to the GLB Act and the privacy rule. Because the vast majority of consumers are familiar with or have experience with a bank, the Agencies used a notice designed for a bank to increase the likelihood that most of the test participants could readily understand the terms in the notice, such as “account balances,” “income,” or “credit history,” which describe information collected and shared by many banks, as well as by many other financial institutions.

The Macro Report presented data on the demographic characteristics of the study participants recruited for the study. Participants at each mall were pre-selected for a representative mix based on gender, age, and education levels, and information on participants' race/ethnicity, income, and household size was obtained at the end of each interview.
64

Since a significant majority of consumers in America receive a financial privacy notice—including from banks, credit unions, securities firms, insurance companies, auto dealers, debt collectors, and payday lenders—the Agencies wanted to ensure that a representative cross-section of consumers be included in the study.

64
Macro Report,
supra
note 34, at 3 & Appendix B; Levy-Hastak Report at 2.

The Agencies hired Macro as an outside independent expert to handle all aspects of the collection and reporting of the study data. Macro conducted all training of field staff, implemented a series of checks to ensure greater accuracy of the study data, reviewed, on an ongoing basis, all daily downloads of data from the field, and coded all of the open-end responses.
65

65
Macro Report,
supra
note 34, at 3-4.

With respect to the comment that the accuracy of the study participants' responses overall was relatively low, the commenter cited the judgment quality measure of the participants' fact-based reasons for choosing the lower sharing bank.
66

While the results showed that most consumers likely have a limited

understanding of information sharing practices after a brief exposure to any of the notice styles, nevertheless the Levy-Hastak Report confirms that overall the Table Notice out-performed the other notices and is the most effective notice of all the privacy notices tested.

66
The commenter looked to the Table Notice score of 40.6% in Table 1 of the Levy-Hastak Report. Levy-Hastak Report at 12. This data evaluated how well study participants could explain their reasons for preferring one bank notice over another where they selected, as their preferred bank, the lower sharing bank. While the commenter pointed to a single measure in the Levy-Hastak Report, the Report relied on a number of accuracy measures that varied in difficulty level.
See, e.g., id.,
Table 3 at 12.

Finally, two commenters requested that if both the model privacy form and the SEC's proposed amendments to its privacy rule, Regulation S-P, were adopted, the SEC should coordinate the compliance dates so as to minimize the compliance burden and the potential for multiple revisions of an institution's privacy notice.
67

The SEC appreciates institutions' desire to minimize revisions to their privacy notices and reduce the costs of compliance with its rules. However, the model privacy form the Agencies are adopting today is just that—a model—and no institution is required to use the model form. A financial institution that intends to use the model privacy notice and minimize potential costs, if any, related to revising its privacy notices in light of amendments to Regulation S-P could begin to use the model form after the compliance date of any final amendments to Regulation S-P.

67

See
Part 248-Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Personal Information, Securities Exchange Act Release No. 57427, Investment Company Act Release No. 28718 (Mar. 4, 2008) [73 FR 13692 (Mar. 13, 2008)].
See also
comment letters of American Council of Life Insurers (May 20, 2009) and Investment Advisers Ass'n (May 29, 2007).

F. Validation Testing

In revising the model form based on public comments and findings from the Levy-Hastak Report, the Agencies streamlined the form to consolidate the information on the front and back sides of a single piece of paper and moved the opt-out information to the bottom of page one. In December 2008, the Agencies engaged Kleimann to conduct validation testing to confirm that these changes would not affect the comprehension, usability, and design integrity of the model form. In particular, Kleimann's new research focused on the placement of the opt-out information on page one. Kleimann conducted targeted in-depth interviews in January and February 2009 to test, revise, and re-test the model form. On February 12, 2009, Kleimann submitted a report to the Agencies, “Financial Privacy Notice: A Report on Validation Testing Results,” with a revised opt-out form recommendation (“Kleimann Validation Report”).
68

68

http://www.ftc.gov/privacy/privacyinitiatives/validation.pdf.

The validation testing examined various formats for displaying opt-out information where the opt-out methods are by toll-free telephone number,
69

the Internet, or a mail-in form. The validation testing confirmed the usability of the following changes to the proposed model form: (1) inserting a new box titled “To limit our sharing” below the disclosure table to inform consumers how they can limit sharing, such as by a toll-free telephone number or online; (2) replacing the “Contact Us” box with a box titled “Questions” following the “To limit our sharing” box; and (3) as applicable, inserting a mail-in form at the bottom of the page, which would require a longer piece of paper.
70

69

See
section _.7(a)(2)(ii)(D) of the privacy rule.

70
Kleimann Validation Report, Appendix E. The Kleimann Validation Report found that the information for telephone or Internet options could be readily displayed on a standard 8½ x 11-inch page, but the addition of a mail-in form required a longer piece of paper.

III. The Final Model Privacy Form

A. Standardization

Like the proposed model privacy form, the final model form uses a standardized format. Some industry commenters expressed support for the standardized format, with one noting that standardized notices would serve as an effective means of allowing consumers to understand in a simple manner companies' information practices.
71

Another commenter pointed to the success of the “Schumer box,” a standardized format that makes the disclosure of credit card terms more accessible to consumers.
72

71
Comment letter of The Direct Marketing Ass'n (May 29, 2007) (commenting that it has an automated software program that allows companies to create a customized privacy notice in a standardized format).

72

See
comment letter of Capital One Financial Corporation (May 29, 2007);
see also
12 CFR 226.5a(a)(2)(i)-(ii).

Privacy and advocacy groups and NAAG supported the proposed standardized format, recognizing the important findings of the research and the model form's structure—in particular the elements on page one—as benefiting both consumers and companies by making the disclosure information accessible.
73

73

See, e.g.,
comment letters of Center for Democracy and Technology (May 29, 2007); National Ass'n of Attorneys General (June 14, 2007); Privacy Rights Clearinghouse (May 16, 2007).
See also
The Center for Information Policy Leadership (May 29, 2007) (recognizing that the proposed model form addresses the requirements of the GLB Act and that the research provided insight into what effectively communicates to consumers, including “important information about how people learn about privacy, about the use of tables to facilitate comparisons across companies, and about the need to inform consumers about why they are receiving a privacy notice”).

A number of industry commenters, however, objected to the standardized form, asserting variously that: It causes confusion; because it is an abrupt change in the way information-sharing practices are disclosed, it could cause consumers to believe that the institution is changing its policies; because the model form has too much boilerplate, it detracts from the ability to compare policies; and it makes the notice less clear. Others stated that the standardized form is too inflexible and does not accurately reflect institutions' financial practices or accurately describe the scope of consumers' rights. Several stated that the model form language does not adequately capture the complex privacy policies and practices of many institutions.

Based on the statutory requirement that the Agencies propose “a model form,” the final model privacy form utilizes a standardized format.
74

Moreover, as more fully discussed in the preamble to the Proposed Rule, the Agencies' research supports uniform disclosures to help consumers better understand companies' information sharing practices.
75

We reaffirm that use of the model form is voluntary; institutions are not required to use it.

74

Cf.
Press Release, U.S. House of Representatives, Committee on Financial Services, Financial Services Committee Democrats Call for Simplified Privacy Notices, (July 25, 2003) available at:
http://financialservices.house.gov/pr062503.html.

75

See
Proposed Rule,
supra
note 4 at text accompanying n.30.
See also
Janice Tsai, Serge Egelman, Lorrie Cranor, and Alessandro Acquisti, “The Effect of Online Privacy Information on Purchasing Behavior: An Experimental Study,” The 6th Workshop on the Economics of Information Society (WEIS) (June 2007)
http://weis2007.econinfosec.org/papers/57.pdf
(more accessible privacy information reduces information asymmetry between the merchant and the consumer as to the use of consumers' personal information; aids consumers in making informed choices; and demonstrates that consumers tend to purchase from merchants offering more privacy protection, including paying a premium for such a purchase).

B. Instructions for Use

The General Instructions to the Model Privacy Form require that no additional information—other than what is specifically permitted—may be included in the model form in order to obtain the benefit of the safe harbor.
76

76

See
Instruction C to the Model Privacy Form.

A number of industry commenters objected to the Agencies' statement in the preamble to the Proposed Rule that the model form should not be incorporated into any other document.
77

Some expressed concern that this would require the notice to be mailed separately.
78

Several commenters stated that a private label or co-branded credit card application incorporates the lender's privacy policy into a brochure with a tear-off application to make it easier for the store clerks to provide all required information in a single document.
79

Others observed that the privacy notice is typically included in a single document with other important reference information.

77

See, e.g.,
comment letters of American Council of Life Insurers (May 29, 2007); Investment Company Institute (May 29, 2007); National Business Coalition on E-Commerce and Privacy (May 30, 2007).

78

See, e.g.,
comment letters of American Bankers Ass'n (May 25, 2007); American Insurance Ass'n (May 29, 2007) Visa U.S.A., Inc. (May 29, 2007).

79

See, e.g.,
comment letters of Consumer Bankers Ass'n (May 29, 2009); National Retail Federation (May 29, 2007).

Recognizing these concerns, the Agencies agree that institutions may incorporate the model form into another document, but they must do so in a way that meets all the requirements of the privacy rule and the model form instructions, including that: The model form must be presented in a way that is
clear and conspicuous;
80

it must be
intact
so that the customer can retain the content of the model form;
81

and it must retain the same
page orientation, content, format, and order
as provided for in this Rule.

80
The term “clear and conspicuous” is defined in the privacy rule at section _.3(b), SEC section 248.3(c), and includes as a requirement that the notice be designed to call attention to the nature and significance of the information in the notice. In addition, the privacy rule requires that consumers should reasonably be expected to receive the notice.
See
section _.9 of the privacy rule.

81
Institutions that incorporate the model privacy form into other documents must take care that the customer's execution of other forms in the document will leave the model form intact.

C. Format of the Notice

In response to numerous comments relating to the format of the proposed model form, the Agencies have revised certain of the requirements relating to paper size, orientation, number of pages, type size, and color and logo placements, as discussed below.

Paper Size:
To allow institutions greater flexibility, the final model privacy form may be printed on paper the size of which must be sufficient to meet the layout and minimum font size requirements with sufficient white space on the top, bottom, and sides of the content.
82

Many industry commenters objected to the proposed requirement that the model form appear on 8
1/2
by 11-inch size paper.
83

Commenters stated that the proposed model form would require significant materials, postage, and production costs. Industry commenters explained that institutions use a variety of sizes and styles to present their privacy notices. Some institutions—particularly credit card institutions—enclose their privacy notices with a billing or periodic statement or a bankcard carrier. Envelopes for certain of these statements or for multi-panel formats are smaller than 8
1/2
inches and may not accommodate the proposed size.

82

See
Instruction B to the Model Privacy Form. The Agencies understand that most privacy policies provide for opting out by toll-free telephone or on the Internet. The paper size for those policies will likely be about 8
1/2
x 11 inches. However, for those institutions that provide a mail-in opt-out form, the paper size will likely need to be longer, around 8
1/2
x 14 inches, in order to accommodate the mail-in form.

83

See, e.g.,
comment letters of Consumer Bankers Ass'n (May 29, 2007); American Bankers Ass'n (May 25, 2007); Bank of America Corporation (May 29, 2007); Independent Community Bankers of America (May 29, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007); Investment Company Institute (May 29, 2007); National Retail Federation (May 29, 2007); National Ass'n of Mutual Insurance Cos. (May 29, 2007); Credit Union National Ass'n (May 29, 2007).

The Agencies have reviewed numerous financial institution privacy notices over the past eight years, many of which are printed on smaller-sized paper in a multi-panel, multi-fold display. The density of the small-font text, in addition to the complex legal language, make these notices very difficult to read or understand.
84

The final requirement for paper size is designed to provide financial institutions with some flexibility, while prohibiting a paper size that is too small to accommodate the font and orientation requirements in the model form set forth below.

84

See supra
notes 24-25 and
infra
note 95.

Orientation:
Like the proposed model form, the final model privacy form must be printed in “portrait” orientation. Some institutions objected to this orientation, suggesting instead that institutions be permitted to design their own model form in other orientations, such as the commonly-used multi-fold display.
85

According to these commenters, this landscape format has three or more “pages” of text visible on each side of the paper when the notice is fully opened. The size of the paper varies considerably, with some as small as approximately 7 by 11 inches before it is folded. In such a display, each “page” is approximately 3
1/3
by 7 inches—considerably smaller than can accommodate the model form.
86

85

See, e.g.,
comment letters of National Retail Federation (May 29, 2007); Investment Advisers Ass'n (May 20, 2009); American Bankers Ass'n (May 25, 2007); Credit Union National Ass'n (May 29, 2007). Some of these commenters pointed to the preamble language in the final privacy rule which states: “The Agencies believe that in most cases the initial and annual disclosure requirements can be satisfied by disclosures contained in a tri-fold brochure.” 65 FR 33646, 33662 (May 24, 2000) (FTC); 65 FR 35162, 35175 (June 1, 2000) (banking agencies); (Regulation S-P) 65 FR 40334, 40347 (June 29, 2000) (SEC). This statement was written in 2000 before the Agencies or institutions had any experience with the GLB Act privacy notices. In the intervening period, both the Agencies and institutions have learned much through their own testing about improved notice design and consumer comprehension. The impetus for the Agencies' consumer research, borne out by the research findings, is that the current notices, including those utilizing multi-fold formats, are not effective. Moreover, the important information on page one of the model form—including the context information and disclosure table—could not be appropriately displayed in such a cramped format and still comply with the minimum space and font requirements of the model form.

86
Examples provided by commenters included: 3.5 x 7.5 inches, printed double sided; 3.5 x 8; 7 ×10.812 inches folded to 7 x 3.625 inches; 7 x 3.5 inches (finished folded size).
See, e.g.,
comment letter of National Retail Federation (May 29, 2007).

The design of the model form does not lend itself to a multi-panel display. The utility of the form's design for reading ease depends in large measure on both larger, more readable type size and how the content is presented. While one commenter objected to the “significant empty space” in the model form,
87

the guidance from communications experts and form designers is that appropriate white space between the text and margins, as well as the use of headings and bullets, make a more effective, readable notice.
88

The table—the heart of the model form—cannot be squeezed into a tighter space or so reduced in size as to make it virtually unreadable. For these reasons, the Agencies do not agree that the orientation of the model form should be altered to accommodate a multi-panel display.

87

See
comment letter of Consumer Bankers Ass'n (May 29, 2007).

88

See supra
note 25.

Number of Pages:
In response to numerous commenters, the instructions to the final model privacy form permit the form to be printed on two sides of a single piece of paper or on two single-sided sheets.
89

By incorporating the opt-out information on the bottom of page one, the revised model form may now appear on the front and back of a single piece of paper.

89

See
Instruction B.2 to the Model Privacy Form.

Industry commenters generally objected to the proposed requirement that the model form be printed only on one side of a page.
90

Many raised environmental concerns and the increased costs associated with printing the notice on multiple pages.

90

See, e.g.,
comment letters of American Insurance Ass'n (May 29, 2007); Bank of America Corporation (May 29, 2007); Citigroup Inc. (May 30, 2007); National Retail Federation (May 29, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007).

While the proposed single-sided model form was based on the initial

consumer research and testing, the Agencies believe that the concerns expressed by commenters justify double-sided printing. Moreover, the Agencies used double-sided printed notices in the quantitative and validation testing, with no demonstrable loss in effectiveness relative to the single-sided notice.
91

91

See
Levy-Hastak Report at 15.

D. Appearance of the Model Privacy Form

The Regulatory Relief Act requires that the model form “use an easily readable type font.” While a number of factors affect the readability of a document, as in the proposal, the final model privacy form must use: (1) 10-point font as the minimum font size (unless otherwise specified in the Instructions) and (2) sufficient spacing between the lines of type (leading).
92

92
While a variety of type styles would be suitable for the model notice, the Agencies caution institutions that use of idiosyncratic fonts or highly stylized typefaces will not meet the model form safe harbor standard.
See
Instruction B.3(a) to the Model Privacy Form.

The Agencies separately provided optional guidance in the preamble to the Proposed Rule on readable type styles and other formatting suggestions for institutions. This optional guidance is not required; it was to assist institutions that want to provide more readable and attractive privacy notices to consumers. The Agencies are republishing this optional guidance in section III.E to assist interested institutions.

Type Size:
A number of commenters expressed various concerns about the proposed 10-point minimum font requirement.
93

A few commenters noted that the proposed model form included several different type sizes for various parts of the model form and were confused about what type size(s) the Agencies proposed as a requirement.
94

Other commenters raised concerns that a minimum type size requirement for the model form would conflict with state law mandated requirements. A few stated that a minimum font size is not legally required for the model form.

93

See, e.g.,
comment letters of American Council of Life Insurers (May 29, 2007); National Business Coalition on E-Commerce and Privacy (May 30, 2007); National Retail Federation (May 29, 2007); Financial Services Roundtable and BITS (May 29, 2007).

94
The type size information in Example 3 in the preamble to the Proposed Rule identified the five type sizes used in various elements of the proposed form. This example was intended solely to show how key features of the form—such as headings—can be distinguished by using different font sizes to make the form more visually appealing. Contrary to some commenters' assumption, the different sizes were not a proposed requirement for users of the model form.

Many of the criticisms about current notices are, in part, about the tiny print that make these notices so difficult for consumers to read.
95

Based on the statutory directive, as well as the findings elicited from the Agencies' consumer research and expert views, the Agencies believe that the model form should have a minimum 10-point font. Requiring a minimum 10-point font is consistent with state law mandates for consumer disclosures.
96

95

See
Kleimann Report,
supra
note 32, at 33.
See also, e.g.,
Public Citizen Petition,
supra
note 24 at 7 (“[S]mall font sizes * * * deprive consumers of their right to prevent financial institutions from sharing private information.”); “UNDERSTANDING THE FINE PRINT: How to make sure the gotchas don't get you,” Consumer Reports Money Adviser (Oct. 2008) (“Fine print is everywhere—contracts; retail Web sites; sales receipts; print, broadcast, and Internet offers; prospectuses; privacy notices; product manuals; and manufacturer warranties.”); David Colker, “Stopping junk mail for living and dead; Opt-outs can slow the torrent of solicitations to computer and postal mailboxes and phones;” Los Angeles Times, July 22, 2007, at C3 (“[B]y law, financial institutions have to offer an opt-out if they are making this data available to non-affiliated businesses. The problem is that their guides to opting out are often contained in their privacy notices—in small print.”).

96

See, e.g.,
Cal. Fin. Code div. 1.2 § 4053(d)(1)(B) (requiring 10-point minimum font).

Leading:
Leading is the spacing between lines of type, measured in points. If the line spacing is too narrow, the type is hard to read. In these circumstances, the ascenders (such as the upward line in the letter “h”) and descenders (such as the downward line in a “g”) may touch, blending the lines of type and making it much harder to distinguish the letters on the page. The final instructions to the model form require only that the leading used allow for sufficient spacing between the lines, but do not mandate a specific amount.

E. Optional General Guidance for Easily Readable Type

The Proposed Rule included optional guidance on readable type styles and other formatting suggestions for institutions that want to provide privacy notices that are more readable and attractive to consumers, as well as those that want to develop their own model privacy form.
97

A number of commenters were concerned by this guidance for easily readable type, and in some cases, they assumed the guidance would be mandatory. The Agencies expressly state that the guidance in this section III.E. is not mandatory and is not a requirement for proper use of the model form.

97

See
Proposed Rule,
supra
note 4, at section II.F.

In more closely examining the statutory directive for “easily readable type,” the Agencies determined that a number of type-related factors can greatly affect the readability of a form. Type size, type style, leading, x-height, serif versus sans serif,
98

upper and lower case type, along with the page layout—together play an important role in designing a typeface that is highly readable. Therefore, in considering these various factors for the design of an easily readable type font, institutions that elect to use the model form may voluntarily consider this additional guidance for an easily readable appearance to the notice.

98
Serif typeface has small strokes at the ends of the lines that form each letter. Sans serif typeface does not have those small strokes.

Leading:
Research on the legibility of typography indicates that people read faster when text is set with 1 to 4 points of leading.
99

Institutions may, but are not required to, consider these general recommendations for use with the model form: 10- or 11-point type should have between 1 and 3 points of leading. Twelve-point type should have between 2 and 4 points of leading.
100

99
Karen A. Schriver, Dynamics In Document Design (“Schriver”) 274 (1997).

100

Id.
at 262;
see also
James Hartley, Designing Instructional Text (1994); and Barbara Chaparro
et al.,
Reading Online Text: A Comparison of Four White Space Layouts 6(2) (2004).

Type style and “x”-height:
The readability of type size is highly dependent on the selection of the type style. Some styles in 10-point font are more readable than others in 12-point font and appear larger because of their design.

Experts differ on the question of the most desirable type style. The model form uses sans serif and “monoweight” type, and upper and lower case lettering in the body of the form.
101

101
While much of the printed material in the United States and western Europe uses serif styles, Web designers are increasingly using sans serif type, as they have found that serif type is harder to read online. These changes in Web design are also beginning to affect font styles in printed materials. Some typography designers are now using sans serif typefaces, as well as type with a uniform thickness throughout the letter (monoweight typeface), finding these typefaces easier to read than those with variable thickness.

Larger x-height
102

makes a font appear larger and thus more readable, and fonts with larger x-heights are better for smaller text. Research shows that our eyes “scan the top of the letters' x-heights during the normal reading process, so that is where the primary identification of each letter takes place.”
103

Generally, a font with an

x-height ratio of around .66 is easier to read.
104

102
The “x-height” is the height of the lower-case “x” in relation to full height letters, such as a capital G. X-height is critical to type legibility.

103
Erik Spiekermann & E.M. Ginger, Stop Stealing Sheep & Find Out How Type Works 93 (1993).

104

See, e.g.,
Hewlett-Packard Corporation, Panose Classification Metrics Guide (2006), available at
http://www.monotypeimaging.com/productsservices/pan2.aspx.

While not mandating a particular type style or x-height, the Agencies are providing these general guidelines for type style in the model form: For typefaces with a smaller x-height, 11- or 12-point font should be used; for typefaces with a larger x-height, a 10-point font would be sufficient.
105

105

See
Schriver,
supra
note 99, at 264;
see also id.
at 258-59. Fonts that satisfy the type style and x-height recommendations include sans serif fonts such as Tahoma, Century Gothic, Myriad, Avant Garde, Bk Avenir Book, ITS Franklin Gothic, Arial-Helvetica, and Gill Sans, and serif fonts such as the Chaparral Pro Family, Minion Pro, Garamond, Monotype Bodoni, and Monotype Century. A number of these font styles, including Arial-Helvetica, Tahoma, Century Gothic, Garamond, and Bodoni, are preloaded in commonly used word processing applications with most new personal computers. The other font styles are commercially available as well.

For ease of reference, the following table summarizes the optional guidance discussed here. None of the standards in the table below is mandatory; rather, the information in the table is offered only as suggestions for institutions that design their own forms.

If
Then use
And use
And use font with

Font is 10-point
1-3 points leading
Monoweight typeface
Large x-height sans serif (around .66 ratio).

Font is 11-point
1-3 points leading
Monoweight typeface
Smaller x-height is acceptable; either serif or sans serif (less than .66 ratio is acceptable).

Font is 12-point
2-4 points leading
Monoweight or variable typeface
Smaller x-height is acceptable; either serif or sans serif (less than .66 ratio is acceptable).

F. Printing, Color, and Logos

We are adopting the requirements for printing, color, and logos in the final model form as proposed. Commenters generally commended the Agencies' support for the use of color and company logos on the model form.
106

A few industry commenters expressed concern about the background shading in certain headers smudging in high-speed printing operations.
107

Some commenters sought clarification as to whether logos can use more than one color.

106

See, e.g.,
comment letters of American Insurance Ass'n (May 29, 2007); National Ass'n of Mutual Insurance Cos. (May 29, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007); Consumer Bankers Ass'n (May 29, 2007).

107

See, e.g.,
comment letters of National Business Coalition on E-Commerce and Privacy (May 30, 2007). With the modern, high-speed printing equipment readily available, the Agencies do not foresee problems with reproducing background shading, just as they see no difficulties with printing blocks of color for company logos or advertising materials. Moreover, the validation testing research found that consumers appreciated shading as a navigation guide.
See
Kleimann Validation Report at 9-10.

The Agencies agree that the distinguishing features of company logos along with color are important to ensure that an institution's documents have a distinctive look that consumers may readily recognize. As the Agencies proposed, a financial institution that uses the model form may include its corporate logo on any of the pages, so long as the logo design does not interfere with the readability of the model form or space constraints of each page. Institutions using the model form should use white or light color paper (such as cream) with black or suitable contrasting color ink. Spot color is permitted to achieve visual interest to the model form, so long as the color contrast is distinctive and the color does not detract from the form's readability. The Agencies are not prohibiting the use of more than one color in a logo.

Other commenters asked for greater flexibility to include “markings” or “graphics” or other “visual effects” or to include a “branding phrase” or “advertising slogan.”
108

The Agencies observe that few institutions' privacy policies include advertising slogans. We note that some include pictures or other large designs that occupy the front cover. The Agencies believe that these designs or slogans would distract from the content of the model form and that slogans would be inconsistent with the standardized language throughout the form. For these reasons, the final model form does not permit institutions to include slogans or images (other than logos) on the model form.

108

See, e.g.,
comment letters of Consumer Bankers Ass'n (May 29, 2007); National Business Coalition on E-Commerce and Privacy (May 30, 2007).

G. Jointly-Provided Notices

The final model privacy form includes a new FAQ at the top of page two: “Who is providing this notice?” Many commenters representing larger institutions observed that the proposed model form did not provide sufficient space to identify multiple entities that jointly provide a privacy notice, as permitted by the privacy rule.
109

Some suggested the Agencies provide extra space for this information either in the body of the notice or as a footnote. The new FAQ is not required where only a single financial institution is providing the notice and that institution is identified in the title. As discussed in section III.J.1, space is provided for the institution's response.

109

See, e.g.,
comment letters of American Council of Life Insurers (May 29, 2007); Investment Advisers Ass'n (May 29, 2007).

H. Use of the Form by Differently-Regulated Entities

A number of commenters sought clarification as to whether institutions regulated by different Agencies could together provide a single joint notice to consumers.
110

Insurance companies and their associations in particular expressed concern that the form did not allow for insurance-specific terminology and potentially put these institutions—regulated by the states—at some risk.
111

110

See, e.g.,
comment letters of National Business Coalition on E-Commerce and Privacy (May 30, 2007); T. Rowe Price Associates, Inc. (May 29, 2007); Financial Services Roundtable and BITS (May 29, 2007); National Ass'n of Mutual Insurance Cos. (May 29, 2007); Investment Company Institute (May 29, 2007).

111

See, e.g.,
comment letters of National Ass'n of Mutual Insurance Cos. (May 29, 2007); American Insurance Ass'n (May 29, 2007); Great-West Life & Annuity Insurance Company (May 29, 2007). In addition to including insurance-specific phrases in the menu of terms for the “What?” box on page one and the collection of information FAQ on page two, the Rule also recognizes that institutions that provide insurance products or services and elect to use this model form can use the word “policy” instead of “account” for the joint accountholder description.
See
Instructions C.2(g)(1) and C.3(a)(5) to the Model Privacy Form. The Agencies have periodically consulted with the NAIC to ensure that the final model form is sufficiently flexible to address the insurance marketplace. The NAIC is continuing to evaluate how best to proceed regarding insurance company use and implementation of the form by individual jurisdictions. This effort may include the NAIC developing a model bulletin for regulatory use or amending its model Privacy of Consumer Financial and Health Information Regulation to replace the

current sample clauses with the new model privacy form.

The Agencies fully intend that differently-regulated entities can provide a single joint notice to consumers by using the final model form. The Agencies have consulted with the NAIC, which submitted a letter with proposed modifications to certain sections of the form. The Agencies have incorporated into the final model form two menus of terms adaptable to the wide range of financial institutions. The menus include both the SEC's and the NAIC's proposals, and enable a variety of institutions, including securities firms and insurance companies, to use the model form, either individually or jointly with other types of financial institutions.

I. Page One of the Model Form

1. Title

The Agencies are adopting the title, “What Does [Name of Financial Institution] Do With Your Personal Information?,” as proposed. One commenter objected to the title, preferring instead to refer to it as a privacy notice.
112

Other commenters who provided sample revised notices also used alternate headings, such as, “our privacy notice for consumers,” “privacy information,” “privacy statement,” and “keeping your information safe and secure.”
113

The research found that the terms “privacy notice” or “privacy policy” deterred consumers from reading the notice.
114

Consumers understood these terms to mean that the institution does not share personal information. The validation testing confirmed the effectiveness of the title.
115

112

See, e.g.,
comment letter of MasterCard Worldwide (May 29, 2007).

113

See, e.g.,
comment letter of Citigroup Inc. (May 30, 2007); Wells Fargo & Company (May 29, 2007); Wachovia Corporation (May 25, 2007); Sovereign Bank (May 21, 2007).

114

See
Kleimann Report,
supra
note 32, at 43, 66-67.

115
Kleimann Validation Report at 8.

2. Key Frame

The Agencies are adopting the basic structure of the key frame as proposed with some language changes to address comments received. Industry commenters raised several objections to the key frame—the “Why?,” “What?,” and “How?” boxes. Their principal concern was the inflexible nature of the information in these boxes. Many commenters took particular issue with the list of information collected and shared, noting that not all institutions collect and share the information listed.
116

These commenters asked for greater flexibility in identifying other types of information that may better relate to their practices. Commenters raised other issues about: vocabulary; the contents and number of the boxes; and the inclusion of certain information not required by the privacy rule. Some commenters proposed moving and deleting phrases—as well as using the phrase “as permitted by law” to describe the types of sharing they can do. Some commenters raised questions about the reference to former customers.

116

See, e.g.,
comment letters of American Bankers Ass'n (May 25, 2007); Investment Company Institute (May 29, 2007); Investment Advisers Ass'n (May 29, 2007).

The Agencies appreciate the various suggestions provided—particularly on vocabulary and the structure and contents of the boxes—but note that the model form was developed through consumer research with the goal of making it understandable to consumers. The Agencies have decided to retain the basic structure and content of the key frame but have made certain modifications.

The Agencies recognize that financial institutions may collect and share types of information other than those listed on the proposed form, including institutions that provide insurance or investment advice or sell securities. The Agencies have, after consulting with the NAIC and based on consideration of the comments received, provided a menu of terms, including each of the terms that was proposed, from which institutions may select to fill in the bracketed boxes.
117

Since all financial institutions collect Social Security numbers, this one term is required in all notices. The terms provided are designed to reflect the range of information typically collected by various types of institutions in language that consumers can more easily understand.

117

See
Instruction C.2(b)(2) to the Model Privacy Form. Similar to the proposal, the final model form requires institutions to provide examples that may be applicable to the institution's collection and sharing practices.

Further, the Agencies have revised the statement about former customers to: “When you are no longer our customer, we continue to share information about you as described in this notice.” While some institutions objected in principle to the statement that former customers are subject to the same policy as current customers,
118

no commenters asserted that institutions actually implement a different policy for former customers.
119

118

See, e.g.,
comment letters of Investment Advisers Ass'n (May 29, 2007); American Insurance Ass'n (May 29, 2007).

119
This sentence continues to appear in the “What?” box in the model form without an opt-out. However, based on the validation testing, the opt-out versions of the model form place this sentence in the “To limit our sharing” box following the sentence describing sharing information about a new customer.
See
Kleimann Validation Report at 9-10.

3. Disclosure Table

We are adopting the disclosure table substantially as proposed, with some minor changes. Consumer and other advocacy groups, the NAIC, NAAG, and some industry commenters appreciated the easily understood display of information in the disclosure table of the proposed model form. One commenter noted the strength of the Schumer box standardized format.
120

Others lauded the use of a tabular format to display a company's sharing practices, noting that framing one institution's practices against the industry as a whole is a useful way to inform consumers of a company's relative sharing practices and facilitates the comparison of different institutions' practices.
121

120
Comment letter of Capital One Financial Corporation (May 29, 2007).

121

See
comment letters of The Center for Information Policy Leadership (May 29, 2007); Independent Community Bankers of America (May 29, 2007).

A number of industry commenters and associations, including many small community banks and a few larger banks, also expressed support for the clarity and consumer-friendly format of the disclosure table.
122

122

See, e.g.,
comment letters of Independent Community Bankers of America (May 29, 2007); Bank of Edison (May 21, 2007); Capital One Financial Corporation (May 29, 2007); Citrus & Chemical Bank (May 24, 2007); First National Bank (Edinburg, TX) (Apr. 9, 2007); Florence Savings Bank (April 30, 2007); Iowa State Bank and Trust Company (May 22, 2007); ShoreBank (Apr. 6, 2007); Hometown Bank (May 8, 2007).

However, many industry commenters sought flexibility in the table design for several reasons. Some reported that it is common for a financial institution to have multiple privacy policies for different products that they offer consumers.
123

Others asserted that the table contains a bias against larger, more complex corporate structures because it is overly simplistic and may show that certain types of institutions engage in widespread sharing.
124

One opined that the table structure made it appear that the entity was reckless in its sharing practices.
125

These commenters expressed particular concern that the model form would lead to high opt-out

rates.
126

Many particularly objected to listing all the categories of sharing—especially when a consumer cannot limit or opt out of certain types of sharing—and others wanted to limit the list only to those categories used by the institution.
127

Some commenters wanted to use this space to explain the benefits of certain types of sharing.
128

Others wanted to convey that, for example, they only shared information with certain types of affiliates but not others and asserted that the disclosure table did not permit them to make this distinction.
129

123

See, e.g.,
comment letters of Bank of America Corporation (May 29, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007); MasterCard Worldwide (May 29, 2007).

124

See, e.g.,
comment letters of Citigroup Inc. (May 30, 2007); Consumer Bankers Ass'n (May 29, 2007).

125

See
comment letter of Consumer Bankers Ass'n (May 29, 2007).

126

See, e.g.,
comment letter of Johnson Financial Group (May 14, 2007).

127

See, e.g.,
comment letters of Huntington National Bank (May 25, 2007); National Business Coalition on E-Commerce and Privacy (May 30, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007).

128

See, e.g.,
comment letter of Consumer Bankers Ass'n (May 29, 2007).

129

See, e.g.,
comment letters of American Council of Life Insurers (May 29, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007); American Insurance Ass'n (May 29, 2007); Consumer Mortgage Coalition (May 29, 2007).

As the Agencies stated in the preamble to the Proposed Rule, based on the Kleimann Report and as confirmed by the quantitative research data and the Levy-Hastak Report, the disclosure table is the heart of the model form design and its most effective feature.
130

The table provides for greater transparency of a company's sharing practices. It allows consumers to see at a glance the types of information sharing a company may engage in, whether that particular company shares in that way, and, if so, whether the consumer can limit such sharing.
131

Based on the research, the Agencies have retained the disclosure table generally unchanged in the final model form.

130

See
Proposed Rule,
supra
note 4, at text preceding and accompanying n.27;
see also
Levy-Hastak Report at 17.

131
The disclosure table in the model form provides information “at-a-glance” that facilitates the comparison of a company's information sharing practices, both as to the industry as a whole and with respect to any other specific companies. In this way, it meets the original legislative intent to easily compare companies' privacy practices.
See
H.R. Rep. No. 106-74, at 107 (1999).

Addressing industry concerns about bias against larger institutions, the Agencies appreciate these institutions' concern that some of their customers may react negatively to the sharing of their information. The purpose of the model form is not to direct consumer behavior, however, but rather to provide information effectively. While the Levy-Hastak Report found that a majority of survey participants objected to the sharing of their personal information with affiliated companies, and more so with nonaffiliated companies, these objections were consistent across all the survey participants and were not affected by any particular notice format.
132

The research confirms that the notice design more clearly informs consumers about how each company shares or uses the personal information it collects.

132
Levy-Hastak Report at 15.

During the course of this project, the Agencies heard from smaller institutions that their customers wanted to stop all sharing and expressly asked for opt-outs even when the institution engaged in only limited sharing under the section __.14 and __.15 exceptions.
133

The neutral design of the form, particularly through the table, explains that some sharing is necessary for an institution's “everyday business purposes” and makes clear what sharing occurs. In addition, the model form uses the term “limiting” sharing, rather than stopping sharing altogether. These small institutions commented that this more balanced presentation of sharing practices is a very important feature of the notice, and one that they welcome, as it makes all institutions' sharing practices more transparent.
134

133
This comment was made by some of the Agencies' regulated entities at various times during the course of this project and was also discussed by members of the Board's Consumer Advisory Council during its discussions in 2007 about the Notice Project and model form proposals.

134

See, e.g.,
comment letter of Independent Community Bankers Ass'n (May 29, 2009).

The strength of the table design is that it facilitates comparison by showing what a particular institution's sharing practices are as compared to what all financial institutions can legally do. For this reason, the final model form incorporates all seven reasons for sharing, with only the affiliate marketing provision—“For our affiliates to market to you”—optional for those companies that elect to incorporate that disclosure in their GLB notices.
135

135

See infra
note 142.

While the middle column requires institutions to answer “yes” or “no” to whether it shares for each of the reasons, some commenters expressed concern that their information sharing practices were sufficiently complex that they could not answer “yes” or “no,” stating that they had different practices for different products. Institutions that elect to use the model form must answer the questions in the final model form as directed in the proposal. If an institution elects to use the model form, it must either harmonize its practices so one notice applies to all its products, or it must provide separate notices for products subject to different information sharing practices.

A few commenters opined that they may not currently share but want to reserve the right to share in the future. In such a case, the correct response in the middle column is “yes,” consistent with the privacy rule.
136

136

See
the privacy rule, section __.6(e), NCUA section 716.6(d) (notices can be based on current and anticipated policies and practices).

Many institution commenters objected that the proposed terms to describe sharing practices were abbreviated or incomplete and asserted that the Agencies limited sharing that is lawfully permitted. For example, commenters objected that the definition of “everyday business purposes” excluded a long list of permissible disclosures designated in sections __.14 and __.15.
137

However, as the Agencies stated in the proposal, the phrase “everyday business purposes” fully incorporates all the disclosures permitted by law under sections __.14 and __.15 of the privacy rule.
138

In addition, the Agencies have determined that service providers that do not fall under section __.14, but perform direct services to the institution such as opt-out scrubbing or market analysis or research under a section __.13 agreement, are included under this provision.
139

137

See, e.g.,
comment letters of American Insurance Ass'n (May 29, 2007); Consumer Bankers Ass'n (May 29, 2007); Citigroup Inc. (May 30, 2007); Securities and Financial Markets Ass'n (May 29, 2007).

138

See, e.g.,
comment letters of American Bankers Ass'n (May 25, 2007); American Insurance Ass'n (May 29, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007). This language substantially replaces the “as permitted by law” phrase used in the Sample Clauses, covering all permitted disclosures—along with the attendant requirements on reuse and redisclosure—found under sections __.14 and __.15 of the privacy rule. Unlike that clause, “everyday business purposes” conveys more concrete information to consumers and, importantly, helps them understand that some sharing is necessary in order to obtain financial products or services.

139
Joint marketing with other financial institutions and section __.13 service providers contracted to do marketing for a financial institution are disclosed separately.
See
Instruction C.2(d)(3) to the Model Privacy Form.

The cited examples of “everyday business purposes”
140

are illustrative only, to enhance consumer understanding. While commenters urged us to include the phrase “as permitted by law” in this description, research has found that consumers are confused and concerned by this phrase; they do not know what it means or what

“laws” it encompasses.
141

Including that phrase would be inconsistent with consumers' need for clear language to understand what their financial institution does with their information.

140
The final model form consolidates all references to “everyday business purposes” in the first reason in the disclosure table, thereby eliminating the illustrative explanation in the “How?” box on page one and the definition on page two.

141

See
Survey Research Center at the University of Georgia, National Ass'n of Insurance Commissioners Insurance Disclosure Focus Group Study (“NAIC Study”), available at
http://www.ftc.gov/os/comments/modelprivacyform/528621-00012.pdf. See also infra
discussion at text accompanying note 221.

Because the laws governing disclosure of consumers' personal information are not easily translated into short, comprehensible phrases, the table uses more easily understandable short-hand terms to describe sharing practices. We do not believe that these short-hand terms diminish the laws' provisions, as some commenters asserted. If, as these commenters suggest, the Agencies add to the laundry list of descriptive terms to make the provisions in the table more “precise,” we believe it will defeat the purpose of making this information more understandable to consumers. Thus, the Agencies have chosen not to provide detailed descriptions for each of the reasons in the table; we re-affirm that institutions' ability to share information in accordance with the statutory provisions would not be limited or otherwise modified by using the model form language.

The phrase “For our marketing purposes” captures the idea that nearly all, if not all, institutions share information to market their own products and services to their customers (for example, using a joint marketing agreement with a service provider such as a bulk mailer or data processor pursuant to section __.13 of the privacy rule) in a manner that does not trigger an opt-out right. Likewise, the phrase “nonaffiliates to market to you” does not diminish the information sharing permitted by the privacy rule, provided that institutions first provide an opportunity for consumers to opt out, as provided for in section __.10 of the privacy rule.

In all these instances, the lack of explicit references in the model form to certain of the exceptions does not mean that an institution cannot take advantage of all the exceptions provided for in the law.

4. FCRA Opt-Outs

The FCRA provisions are adopted in the model privacy form as proposed.
142

A number of industry commenters objected that the disclosure table did not provide a sufficiently complete or accurate description of the affiliate sharing provisions of the FCRA.
143

They urged the Agencies to revise these provisions to more precisely distinguish between the different types of information that can be shared with affiliates (both with and without an opt-out), to describe the applicable exceptions, and to more accurately describe the opt-out pertaining to information that can be used by affiliates for marketing.

142
The table includes, as an optional disclosure, the opt-out required by section 624 of the FCRA (reason 6 in the table), 15 U.S.C. 1681s-3 (affiliate use of information for marketing), as added by section 214 of the Fair and Accurate Credit Transactions Act of 2003 (FACT Act), Public Law No. 108-159, 117 Stat. 1952. Section 624 generally provides that information that may be shared among affiliates—including transaction and experience information and certain creditworthiness information—cannot be used by an affiliate for marketing purposes unless the consumer has received a notice of such use and an opportunity to opt out, and the consumer does not opt out. Congress did not grant the CFTC rulemaking authority to implement section 624. The other Agencies have issued final regulations implementing the affiliate marketing provision of the FACT Act, 12 CFR part 41 (OCC), 12 CFR part 222 (Board), 12 CFR part 334 (FDIC), 12 CFR part 571 (OTS), 12 CFR part 717 (NCUA), 16 CFR parts 680 and 698 (FTC), 17 CFR part 248, subpart B (SEC) (“affiliate marketing rule”). Because the Agencies' affiliate marketing rules generally use consistent section numbering, relevant sections will be cited, for example, as “section _.23” unless otherwise noted. The affiliate marketing rule included language stating that the section 624 disclosure as it appears in the model form will meet the requirements of that rule.
See
72 FR 61424, 61452 (Oct. 30, 2007) (FTC); 72 FR 62910, 62932 (Nov. 7, 2007) (banking agencies); 74 FR 40398, 40418 (Aug. 11, 2009) (SEC) (“use of the [GLB Act] model privacy form will satisfy the requirement to provide an initial affiliate marketing opt-out notice”).
See also
section __.23(b) of the affiliate marketing rule.

143

See, e.g.,
comment letters of Citigroup Inc. (May 30, 2007); American Bankers Ass'n (May 25, 2007); Consumer Bankers Ass'n (May 29, 2007); National Business Coalition on E-Commerce and Privacy (May 30, 2007); Visa U.S.A, Inc. (May 29, 2007).

The FCRA statutory provisions are quite complex and their legal intricacies are difficult for consumers to understand. The Agencies found through the consumer testing conducted by Kleimann that the short-hand FCRA terms used in the model form describing the types of personal information that can be shared with affiliates are sufficient to enable consumers to make informed decisions about such sharing. Again, these short-hand terms do not in any way diminish or modify the affiliate sharing provisions of the FCRA.
144

To give some meaning to the statutory term “other information,” the disclosure table uses “Information about your creditworthiness”—a short-hand phrase that consumers reasonably understood. Testing also found that consumers reasonably understood the phrase “information about your transactions and experience” without further embellishment.
145

144

See
section 603(d)(2)(A) of the FCRA relating to the sharing of “transaction and experience information” and the sharing of “other information” which triggers an opt-out notice.

145
Kleimann Report,
supra
note 32, at 63.

Some institutions objected to the description of the optional affiliate marketing provision enacted under the FACT Act for which the Agencies have published final regulations.
146

These commenters are correct that this provision, unlike the others, is about the
use
of shared information for marketing. While the Agencies and Kleimann worked to ensure accuracy in the model form, it was evident at the outset that this particular provision would be very difficult to explain in a simple and clear way to consumers and be precisely true to the statutory language.

146

See supra
note 142.

The final formulation we proposed tested sufficiently well to show that consumers understand its basic meaning.
147

Including the affiliate marketing notice and opt-out in the model form is optional. Institutions that are required to provide this notice, and elect not to include it in their GLB Act privacy notice, must separately send an affiliate marketing notice that complies fully with the affiliate marketing rule requirements.

147
Levy-Hastak Report at 15.

For those institutions that elect to incorporate this provision in the model form, the Agencies believe that it is simpler and less confusing to consumers for the affiliate marketing opt-out to be of indefinite duration, consistent with the opt-out required under the GLB Act. If an institution elects to limit the time period for which the opt-out is effective, as permitted under the affiliate marketing rule, it must not include the affiliate marketing opt-out in the model form. Instead, the institution must comply separately with the specific affiliate marketing rule requirements.

5. Limiting Sharing: Opt-Out Information

In response to commenters and the results of the quantitative testing, the final model form includes opt-out information for those institutions that are required to provide an opt-out on the bottom of page one. The Agencies proposed that the information about limiting or opting out of certain sharing, as needed, would be provided on a separate third page. Many commenters objected to the use of a separate piece of paper for this information, particularly if the notice itself is quite short.
148

148

See, e.g.,
comment letters of American Council of Life Insurers (May 29, 2007); National

Automobile Dealers Ass'n (May 29, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007).

This change eliminates the extra page from the proposed model form and places this important information on the first page that the consumer sees. In addition to the model form with no opt-out, the Agencies are providing two alternate versions to be used, as appropriate, depending on whether the institution offers the option to limit information sharing by mail.
149

149
Some commenters asked about providing the opt-out in an in-person transaction so that the customer could execute the opt-out at that time or could deliver the completed opt-out form in person. The privacy rule does not preclude obtaining a consumer's opt-out election in person. However, while an institution may accept an opt-out election from a consumer in person, requiring a consumer to obtain an opt-out form at a branch office as the
only
means to opt out violates the privacy rule.
See
sections _.7(h), _.9(a) and (b), and _.10(a)(1) and (a)(3) of the privacy rule.

Institutions using the model form must include the opt-out section in their notices only if they (1) share or use information in a manner that triggers an opt-out, or (2) choose to provide opt-outs beyond what is required by law. Financial institutions that provide opt-outs are not required to provide all the opt-out choices and methods described in the model form; they should select those that accurately reflect their practices.
150

150
Institutions that do not include the affiliate marketing disclosure on the model privacy form must not include the affiliate marketing notice or opt-out on the model form mail-in form; that notice must be provided in accord with the affiliate marketing rule, outside the model form.

A number of commenters objected to the statement describing the time period before information can first be shared according to an institution's privacy policy.
151

Recognizing that institutions will provide this form both to new customers and annually to existing customers, the Agencies have modified the language accordingly.
152

The revised model form allows institutions to insert a time period that is 30 days or longer from the date the notice was sent before it can begin sharing for new customers. Some commenters opined that in certain instances they should be able to require the consumer to make an opt-out decision at the time of the in-person or electronic transaction rather than waiting 30 days. While the Agencies recognize that certain situations may warrant an immediate decision, the basic rule is to allow a “reasonable” opportunity to opt out.
153

151

See, e.g.,
comment letters of Bank of America Corporation (May 29, 2007); Wells Fargo & Company (May 29, 2007); Securities Industry and Financial Markets Ass'n (May 29, 2007); American Council of Life Insurers (May 29, 2007).

152
The revised language states: “If you are a new customer, we can begin sharing your information [30] days from the date we sent this notice.”
See also supra
note 119.

153

See, e.g.,
sections _.10(a)(1)(iii) and _.10(a)(3)(iii) of the privacy rule.

Telephone and online opt-outs should closely match the options provided in the form. Consistent with the direction provided in the affiliate marketing rule,
154

the Agencies also contemplate that a toll-free telephone number would be adequately designed and staffed to enable consumers to opt out in a single telephone call. In setting up a toll-free telephone number that consumers may use to exercise their opt-out rights, institutions should minimize extraneous messages directed to consumers who are in the process of opting out.

154

See
72 FR 61424, 61448 (Oct. 30, 2007) (FTC); 72 FR 62910, 62935 (Nov. 7, 2007) (banking agencies); 74 FR 40398, 40421 (August 11, 2009) (SEC).

A number of industry commenters requested clarification on how joint accountholders would be treated.
155

The Agencies have addressed this question with a new FAQ, described below. Further, if an institution elects to provide a choice for the joint accountholder to apply the opt-out only to that joint accountholder, that option must be provided in the telephone or Web prompt, as well as presented in the left-hand box on the mail-in form.
156

155

See, e.g.,
comment letters of American Bankers Ass'n (May 25, 2007); Discover Bank (May 29, 2007).

156

See also
privacy rule, section _.7(d), NCUA section 716.7(d)(6).

A number of commenters from both industry and advocacy groups addressed the question whether consumers need to provide personal information such as a Social Security number, account number, or other identification number in order to opt out. The consumer advocacy organizations, some industry commenters, and an industry association proposed omitting the account number field from the proposed form to reduce the risk of fraud.
157

These commenters expressed concerns about phishing and identity theft, and were especially concerned about institutions' use of the Social Security number to confirm an opt-out request. These commenters argued that a name and address should be sufficient to effect an opt-out from an institution's information sharing.

157

See, e.g.,
comment letters of Center for Democracy and Technology (May 29, 2007); Privacy Rights Clearinghouse (May 22, 2007); National Automobile Dealers Ass'n (May 29, 2007.

Many institutions argued that they needed a Social Security number or full account or policy number in order to authenticate the person who wanted to opt out or to apply the opt-out appropriately to all accounts held by the customer or only to specific accounts.
158

Some industry commenters urged limiting the information to only the last four digits of an account number as both safe for the consumer and sufficient to implement the opt-out.
159

158

See, e.g.,
comment letters of National Retail Federation (May 29, 2007); Citicorp (May 29, 2007); National Business Coalition on E-Commerce and Privacy (May 30, 2007).

159

See, e.g.,
comment letters of Sun Trust Banks, Inc. (May 23, 2007); Central National Bank of Enid (May 24, 2007).

Having considered these comments and the context in which such sensitive information is used—to implement an opt-out for information sharing—the Agencies strongly encourage institutions to use some other form of identifier, such as a randomly generated “opt-out code” provided in the notice that consumers can use to exercise their opt-outs without jeopardizing the security of their most sensitive personal information. A random code—which some institutions currently use—both protects consumers' most sensitive information and at the same time can be used to link both the customer and account(s) to which the opt-out should apply. Such an approach would further simplify the opt-out process for consumers. If such an approach is not feasible, institutions could use a truncated account or policy number to protect sensitive information.
160

Of course, any opt-out means provided—including any information requirements imposed on consumers—must be reasonable under the privacy rule and reasonable and simple under the affiliate marketing rule.
161

Institutions should keep these requirements in mind when requesting information beyond the consumer's name and address.

160

See also
The President's Identity Theft Task Force, Combating Identity Theft, at 13 (Apr. 2007) (“Consumer information is the currency of identity theft, and perhaps the most valuable piece of information for the thief is the SSN”).

161

See
section __.7(a)(1)(iii) of the privacy rule and section _.25(a) of the affiliate marketing rule.

A number of industry commenters objected to the inability of the model form to provide for partial opt-outs, as permitted by the privacy rule.
162

The Agencies have observed that partial opt-outs are not widely employed. Trying to incorporate partial opt-outs in this model form would be unduly complicated and confusing for consumers, so the Agencies have determined to use the default provision of the privacy rule that provides for an opt-out that applies to all inform

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3AE9-27882. Public record. Not legal advice.
