Understanding Regulation P: How Financial Institutions Must Protect Your Privacy
A practical guide to how Regulation P protects your financial privacy, limits data sharing, and gives you the right to opt out.
Regulation P, issued by the Consumer Financial Protection Bureau (CFPB), sets federal rules for how many financial institutions collect, use, and share your nonpublic personal information and what privacy notices and choices they must provide you.
This guide explains in plain language what Regulation P requires, what counts as protected information, how your data may be shared, and which rights you can exercise to limit that sharing.
1. What Regulation P Is and Why It Exists
Regulation P implements the privacy provisions of the Gramm–Leach–Bliley Act (GLBA), a federal law designed to ensure that consumers receive clear information about how their financial data is used and have some control over certain disclosures.
In broad terms, Regulation P:
- Requires many financial institutions to provide privacy notices describing their data practices.
- Limits when they can share nonpublic personal information with nonaffiliated third parties.
- Gives consumers the right to opt out of some types of information sharing.
- Restricts the redisclosure and reuse of information once it has been shared.
- Prohibits sharing account numbers with certain third parties for marketing purposes, with narrow exceptions.
1.1 Who Must Follow Regulation P
Regulation P applies to a wide range of entities that are considered financial institutions under GLBA and that are subject to CFPB rulemaking authority. These can include, for example:
- Banks and savings associations
- Credit unions
- Mortgage lenders and brokers
- Nonbank lenders and finance companies
- Certain investment and insurance intermediaries, depending on structure and activity
The rule focuses on information about individuals who obtain financial products or services for personal, family, or household purposes, not on businesses or commercial customers.
1.2 Purpose and Scope at a Glance
| Feature | What It Means Under Regulation P |
|---|---|
| Purpose | Regulates how covered financial institutions treat nonpublic personal information about consumers and requires privacy notices and opt-out rights. |
| Who is covered | Financial institutions under CFPB authority that provide products or services to individuals for personal, family, or household use. |
| Who is not covered | Information about companies, or individuals using services for business, commercial, or agricultural purposes. |
| Core obligations | Provide privacy notices; limit disclosure of nonpublic personal information; provide opt-out opportunities; comply with reuse/redisclosure limits. |
2. Key Concepts: Consumers, Customers, and Nonpublic Personal Information
To understand Regulation P, you need to know how it defines consumer, customer, and nonpublic personal information (NPI).
2.1 Consumers vs. Customers
- Consumer: An individual who obtains a financial product or service from a covered institution, primarily for personal, family, or household purposes.
- Customer: A consumer who has an ongoing customer relationship (for example, a checking account or home mortgage), not just a one-time transaction.
The distinction matters because certain notices, such as annual privacy notices, focus on customers, while some protections apply more broadly to any consumer whose nonpublic personal information is collected.
2.2 What Counts as Nonpublic Personal Information
Regulation P protects nonpublic personal information about a consumer, which includes both:
- Personally identifiable financial information provided by the consumer or obtained in connection with a financial product or service.
- Lists or groupings of consumers derived from such information.
Examples of personally identifiable financial information include:
- Data on loan or credit card applications (income, assets, contact information)
- Account balances, payment and overdraft history, and transaction records
- The fact that a person is a customer or has obtained a financial service
- Information obtained during loan servicing or collections
Information that is publicly available (such as information listed in a public telephone directory or publicly recorded liens) is generally not treated as nonpublic personal information when it truly comes from public sources, but blending public data with private details can still create protected NPI.
3. Privacy Notices: Initial, Annual, and Revised
One of the most visible parts of Regulation P is the requirement for financial institutions to provide clear privacy notices that accurately describe their data practices.
3.1 Initial Privacy Notice
When a consumer becomes a customer, the institution generally must provide an initial privacy notice that describes, among other things:
- What categories of nonpublic personal information it collects
- How it uses and shares that information
- The categories of affiliates and nonaffiliated third parties with whom it may share information
- The consumer’s right to opt out of certain disclosures, and how to exercise that right
- How it protects the confidentiality and security of information
The CFPB provides a model privacy form that institutions can use to simplify compliance and present standardized, consumer-friendly disclosures.
3.2 Annual Privacy Notice
For as long as a customer relationship exists, the institution historically had to send an annual privacy notice describing its current practices, with some later statutory and regulatory adjustments allowing relief in limited circumstances when data-sharing practices do not change and are restrictive. The notice must remain accurate and consistent with what the institution actually does with consumer information.
3.3 Revised Notices When Practices Change
If a financial institution wants to start using or sharing information in a way that is not described in its current notice, it typically must:
- Provide a revised privacy notice describing the new practices; and
- Give affected consumers a new opt-out opportunity before making certain additional disclosures.
4. Limits on Sharing Information With Nonaffiliated Third Parties
Regulation P places specific limits on how financial institutions can disclose nonpublic personal information to nonaffiliated third parties (companies that are not under common control or ownership with the institution).
4.1 Conditions for Sharing
As a general rule, with some exceptions, a financial institution may not disclose nonpublic personal information about a consumer to a nonaffiliated third party unless all of the following conditions are met:
- The institution has provided an initial privacy notice describing the practice.
- The institution has provided a clear opt-out notice explaining the consumer’s right to say no to that sharing.
- The consumer has been given a reasonable opportunity to opt out before the information is disclosed.
- The consumer does not opt out.
4.2 What Is a “Reasonable Opportunity” to Opt Out?
Regulation P provides examples of what counts as a reasonable opportunity to opt out. For instance:
- By mail: Mailing the notice and allowing 30 days for the consumer to mail back a form, call a toll-free number, or use another reasonable method.
- By electronic delivery: Providing online notices and a simple electronic opt-out process, with a similar time window.
- One-time transactions: Presenting the notice and opt-out choice as part of completing an isolated transaction, such as issuing a cashier’s check, and requiring the consumer to decide before completion.
These examples show that both the time period and the practical ease of opting out are important.
4.3 Application to All Consumers and All Data
Institutions must comply with the opt-out requirements even when there is no ongoing customer relationship—for example, where they hold information about a consumer who only completed a one-time transaction. If a consumer opts out, the institution generally may not disclose any nonpublic personal information it has collected about that consumer, whether obtained before or after the opt-out, except as permitted by the rule’s exceptions.
5. Exceptions, Redisclosure Limits, and Account Number Rules
Regulation P includes important exceptions that allow some disclosures without an opt-out, as well as specific limits on redisclosing information and using account numbers for marketing.
5.1 Common Exceptions to the Opt-Out Requirement
Although details appear in several sections of the rule, common categories where information may be shared without providing an opt-out opportunity include:
- Disclosures necessary to process transactions or maintain accounts (such as to payment networks, clearinghouses, or service providers).
- Disclosures required or permitted by law or regulation (for example, to respond to subpoenas, law-enforcement requests, or examinations by regulators).
- Disclosures to service providers and joint marketing partners, subject to conditions designed to protect the information and restrict its use.
Even when these exceptions apply, institutions remain responsible for maintaining the confidentiality and security of consumer information.
5.2 Redisclosure and Reuse Limits
Once a nonaffiliated third party receives nonpublic personal information from a financial institution, that third party is generally restricted in how it may redisclose or reuse the information, depending on which GLBA exception applied to the initial disclosure.
In effect, the privacy protections “follow” the information downstream, preventing it from being freely traded or repurposed in ways inconsistent with the original terms under which it was shared.
5.3 Special Rule for Account Numbers and Marketing
Regulation P also limits the sharing of account numbers or similar access numbers with nonaffiliated third parties for use in marketing.
This is intended to reduce the risk that marketers could directly charge a consumer’s account or use account identifiers in targeted solicitations without stronger protections.
6. The CFPB Model Privacy Form
To promote clarity and consistency, the CFPB has adopted a standardized model privacy form that financial institutions may use to comply with notice requirements.
6.1 Why the Model Form Matters
The model form is designed so consumers can more easily compare privacy practices across institutions. It uses standardized sections and language, and it covers topics such as:
- What the institution does with personal information
- Whether and how consumers can limit certain sharing
- What types of information are collected and shared (for example, income, account balances, payment history, credit history, and more)
- How the institution protects information
Using the model form can provide a form of compliance “safe harbor” for institutions while making it easier for consumers to understand disclosures.
6.2 Opt-Out Language in the Model Form
Where an institution allows consumers to limit sharing with nonaffiliated third parties for marketing, the mail-in or electronic opt-out portion must include clear statements such as: for example, a directive not to share personal information with nonaffiliates to market their products and services. The model form prescribes specific phrasing and structure to improve clarity and comparability.
7. Practical Tips for Consumers
While Regulation P is aimed at institutions, consumers can take active steps to protect their privacy within this framework.
7.1 How to Use Privacy Notices
- Read privacy notices when you open accounts. Look for sections explaining what information is collected and how it is shared.
- Check the opt-out instructions. Notices should explain whether you can limit certain sharing and how (mail, phone, online, or in person).
- Keep copies. Saving notices makes it easier to compare changes if you receive revised versions in the future.
7.2 Exercising Your Opt-Out Rights
- Respond promptly. Take advantage of the reasonable opportunity period (for example, 30 days after receiving the notice by mail) to opt out if you choose.
- Document your request. Keep confirmation numbers, emails, or mailed forms to prove you opted out.
- Review new notices carefully. If practices change and you receive a revised notice, check whether you want to adjust your preferences.
7.3 Understanding the Limits of Regulation P
Consumers should also know that Regulation P:
- Does not generally cover information about business or commercial accounts.
- Coexists with other laws, such as the Fair Credit Reporting Act (FCRA), which may add separate opt-out rights for sharing certain information with affiliates or for using consumer report data.
- Does not prevent all data sharing; some disclosures are allowed or required even without opt-out rights, particularly for transactions and legal obligations.
8. Frequently Asked Questions (FAQs)
Q1: Does Regulation P apply to every company that holds my data?
No. Regulation P applies to entities that meet the definition of a financial institution under GLBA and are within the CFPB’s rulemaking authority. Many non-financial companies, such as retailers or social media platforms, are not covered by this rule, though they may be subject to other federal or state privacy laws.
Q2: Can a financial institution share my information with its affiliates without giving me an opt-out?
Regulation P primarily governs sharing with nonaffiliated third parties. Sharing with affiliates is also regulated, but many of those rules arise under the Fair Credit Reporting Act and related provisions, which may provide additional opt-out rights for certain information sharing.
Q3: If I opt out once, do I need to do it again every year?
Generally, an opt-out under Regulation P continues to apply unless you revoke it, although an institution may provide updated choices if it changes its practices or offers new sharing options. Always review revised privacy notices to see whether a new response is required for new types of sharing.
Q4: Does Regulation P give me the right to access or delete my data?
Regulation P focuses on notice and limits on disclosure, not on broad access, correction, or deletion rights. Some of those rights may be available under other laws (such as FCRA for credit report data) or under state privacy statutes, depending on where you live.
Q5: How do I know whether my bank is compliant with Regulation P?
You should receive a clear privacy notice when you open an account and, in most cases, periodic notices afterward if practices are unchanged or revised. The notice should explain data collection, sharing practices, and opt-out rights. If you believe an institution is not complying, you may submit a complaint to the CFPB or another appropriate regulator.
References
- § 1016.1 Purpose and scope. — Consumer Financial Protection Bureau. 2012-12-31. https://www.consumerfinance.gov/rules-policy/regulations/1016/1/
- § 1016.10 Limits on disclosure of nonpublic personal information to nonaffiliated third parties. — Consumer Financial Protection Bureau. 2012-12-31. https://www.consumerfinance.gov/rules-policy/regulations/1016/10/
- § 1016.3 Definitions. — Consumer Financial Protection Bureau. 2012-12-31. https://www.consumerfinance.gov/rules-policy/regulations/1016/3/
- Privacy of Consumer Financial Information (Regulation P). — Consumer Financial Protection Bureau. 2023-01-01 (current as of access). https://www.consumerfinance.gov/rules-policy/regulations/1016/
- Appendix to Part 1016 – Model Privacy Form. — Consumer Financial Protection Bureau. 2012-12-31. https://www.consumerfinance.gov/rules-policy/regulations/1016/A/
- Privacy of Consumer Financial Information (Regulation P). — National Credit Union Administration, Federal Consumer Financial Protection Guide. 2021-03-01. https://ncua.gov/regulation-supervision/manuals-guides/federal-consumer-financial-protection-guide/compliance-management/deposit-regulations/privacy-consumer-financial-information-regulation-p
- 12 CFR Part 1016 – Privacy of Consumer Financial Information (Regulation P). — Electronic Code of Federal Regulations (eCFR), Office of the Federal Register. 2024-09-10 (current as of access). https://www.ecfr.gov/current/title-12/chapter-X/part-1016
- Overview of Federal Consumer Privacy and Security Laws for Financial Services. — Federal Reserve Bank of Philadelphia, Consumer Compliance Outlook. 2021-10-01. https://www.consumercomplianceoutlook.org/2021/third-issue/overview-of-federal-consumer-privacy-and-security-laws-for-financial-services/
Read full bio of medha deb





