CIPP/US Study Guide
Chapter 9: Financial Privacy

The FAST Act GLBA Annual-Notice Exception and the TaxSlayer Case

The FAST Act (December 2015) amended GLBA section 503 so a financial institution may skip the annual privacy notice if it triggers no opt-out and has not changed its policies. The TaxSlayer FTC matter shows how the GLBA Safeguards Rule and GLBA Privacy Rule apply to a single failure.

The FAST Act, enacted in December 2015, amended GLBA section 503. Under the amendment a financial institution is not required to deliver an annual privacy notice when both of two conditions are met.

  • It shares nonpublic personal information with nonaffiliated third parties only in ways that do not trigger an opt-out right; and
  • It has not changed its privacy policies since the last notice it provided.

Both conditions must hold. If either changes, the obligation to send the annual notice returns.

Two conditions, both required

The exception applies only when there is no opt-out-triggering sharing AND no change in privacy policy since the last notice. Failing either one alone removes the exception.

In the TaxSlayer matter, the FTC examined an online tax-preparation service whose accounts, about 9,000, were accessed by hackers who used them to file fraudulent returns. The FTC alleged TaxSlayer failed to implement adequate authentication and failed to provide a clear privacy notice. The settlement barred TaxSlayer from violating the GLBA Privacy and Safeguards Rules for 20 years.

Mapping TaxSlayer's failures to the two GLBA rules
Alleged failureRule implicated
Inadequate authentication allowing account takeoverGLBA Safeguards Rule
Failure to provide a clear privacy noticeGLBA Privacy Rule

Key terms - quick answers

What is “FAST Act”?
The Fixing America's Surface Transportation Act (December 2015), which amended GLBA section 503 to create an exception to the annual privacy notice requirement.
What is “GLBA Privacy Rule”?
The GLBA rule governing notice of privacy practices and the consumer's opt-out right regarding sharing of nonpublic personal information with nonaffiliated third parties.
What is “GLBA Safeguards Rule”?
The GLBA rule requiring financial institutions to develop, implement, and maintain administrative, technical, and physical safeguards to protect customer information, including adequate authentication.