D.C. Mun. Regs. tit. 26, r. 26-A3604

Current through Register Vol. 71, No. 49, December 6, 2024
Rule 26-A3604 - LIMITATION ON DISCLOSURE OF NONPUBLIC PERSONAL INFORMATION ABOUT CONSUMERS TO NONAFFILIATED THIRD PARTIES
3604.1

Except as otherwise authorized in this regulation, a licensee may not, directly or through any affiliate, disclose any nonpublic personal information about a consumer to a nonaffiliated third party unless:

(a) The licensee has provided to the consumer an initial notice as required under § 3601;
(b) The licensee has provided to the consumer an opt out notice as required in § 3605;
(c) The licensee has given the consumer a reasonable opportunity, before the time that it discloses the information to the nonaffiliated third party, to opt out of the disclosure; and
(d) The consumer does not opt out.
3604.2

Opt out means a direction by the consumer that the licensee shall not disclose nonpublic personal information about that consumer to a nonaffiliated third party, other than as permitted by §§ 3606, 3607 and 3608.

3604.3

A licensee provides a consumer with a reasonable opportunity to opt out if the licensee mails the notices required in § 3604.1 to the consumer and allows the consumer to opt out by mailing the form, calling a toll free number or any other reasonable means within a minimum of 30 days from the date the licensee distributed the notice.

3604.4

For an isolated transaction, such as the purchase of travel insurance for a single trip, or providing the consumer with an insurance quote, the licensee provides a reasonable opportunity to opt out if it provides the consumer with the required notices at the time of the transaction and request that the consumer decide, as a necessary part of the transaction, whether to opt out before completing the transaction.

3604.5

A licensee shall comply with the applicable opt out requirements, regardless of whether the licensee and the consumer have established a customer relationship.

3604.6

Unless a licensee complies with this section, the licensee may not, directly or through any affiliate, disclose any nonpublic personal information about a consumer that it has collected, regardless of whether the licensee collects it before or after receiving the direction to opt out from the consumer.

3604.7

A licensee may allow a partial opt out to a consumer to select certain nonpublic personal information or certain nonaffiliated third parties with respect to which the consumer wishes to opt out.

3604.8

A licensee may require each consumer to opt out through a specific means, as long as that means is reasonable for that consumer.

D.C. Mun. Regs. tit. 26, r. 26-A3604

Emergency Rulemaking published at 47 DCR 9052(November 10, 2000) [EXPIRED]; Emergency Rulemaking published at 48 DCR 2356(March 16, 2001) [EXPIRED]; as Emergency Rulemaking published at 48 DCR 6119(July 1, 2001) [EXPIRED]; as Final Rulemaking published at 48 DCR 8005 (August 24, 2001)