CRCM Privacy and Data Security Compliance 1 β Questions and Answers
Question 1: Under the Gramm-Leach-Bliley Act's Safeguards Rule, financial institutions are required to:
- Encrypt all customer data with AES-256 by default
- Develop, implement, and maintain a comprehensive information security program (Correct answer)
- Report all data incidents to FinCEN within 24 hours
- Hire a Chief Information Security Officer with at least 10 years of experience
Correct answer: Develop, implement, and maintain a comprehensive information security program
The GLBA Safeguards Rule requires financial institutions to have a written comprehensive information security program protecting customer financial information.
Question 2: The FTC's Safeguards Rule (updated 2023) requires covered financial institutions to designate:
- A board-level Privacy Committee
- A qualified individual to oversee the information security program (Correct answer)
- An external auditor to certify the program annually
- A dedicated compliance hotline for data breach reports
Correct answer: A qualified individual to oversee the information security program
The updated FTC Safeguards Rule requires covered institutions to designate a qualified individual (e.g., CISO) to oversee the information security program.
Question 3: Under the GLBA Privacy Rule, a financial institution must provide customers the right to opt out of:
- All data collection by the institution
- Sharing nonpublic personal information with nonaffiliated third parties (Correct answer)
- Receiving account statements by mail
- Receiving marketing calls from affiliated companies
Correct answer: Sharing nonpublic personal information with nonaffiliated third parties
The GLBA Privacy Rule gives customers the right to opt out of sharing their nonpublic personal information with unaffiliated third parties.
Question 4: Under the Bank Service Company Act, when a bank contracts with a third party for services, the bank's compliance obligations:
- Transfer entirely to the third-party vendor
- Remain with the bank; it cannot outsource its compliance responsibilities (Correct answer)
- Are split 50-50 between the bank and vendor
- Apply only to services over $1 million in annual contract value
Correct answer: Remain with the bank; it cannot outsource its compliance responsibilities
Banks cannot outsource their compliance responsibilities; they remain responsible for compliance even when services are performed by third-party vendors.
Question 5: A notification to customers affected by a data breach is required under:
- BSA/AML regulations exclusively
- A combination of federal agency guidance and state data breach notification laws (Correct answer)
- HMDA reporting requirements
- The Community Reinvestment Act
Correct answer: A combination of federal agency guidance and state data breach notification laws
Data breach notifications are governed by both federal agency guidance (OCC, FDIC, Federal Reserve) and state-level data breach notification statutes.
Question 6: Which section of the GLBA covers the financial privacy provisions and requires initial and annual privacy notices?
- Title I (Bank Affiliations)
- Title V (Privacy of Consumer Financial Information) (Correct answer)
- Title II (Functional Regulation)
- Title IV (Unilateral Banking)
Correct answer: Title V (Privacy of Consumer Financial Information)
Title V of the GLBA contains the privacy provisions requiring financial institutions to provide privacy notices and honor opt-out rights.
Under the Gramm-Leach-Bliley Act's Safeguards Rule, financial institutions are required to: