Sitonce
Country: HK
Show exams for United States Hong Kong
Sign in

When Regulation P Requires an Annual Privacy Notice

Updated 5 min read
Key takeaway

Regulation P § 1016.5 generally requires a financial institution to provide each customer with an accurate privacy notice at least once in any period of 12 consecutive months while the customer relationship continues.

More key points
  • An exception can apply when the institution shares nonpublic personal information only under specified exceptions and has not changed its policies or practices in a way that would require a revised notice.
  • If the institution later loses eligibility for the exception, it must resume notices as the rule specifies.
On this page6 sections
  1. General annual rule
  2. Limited exception
  3. If the institution’s practices change
  4. Practical application and common errors
  5. Workflow checks and scenario
  6. Exam takeaway

The annual privacy notice rule applies to customers, not every person who receives a one-time service. Regulation P defines the continuing customer relationship and provides a limited exception for some institutions that do not share information beyond specified purposes.

General annual rule

Under 12 C.F.R. § 1016.5(a), a financial institution must give customers a clear and conspicuous notice accurately reflecting its privacy policies and practices at least annually during the continuation of the customer relationship. “Annually” means at least once in any period of 12 consecutive months. The institution can define that period but must apply it consistently.

Limited exception

Section 1016.5(e) provides an exception when the institution shares nonpublic personal information only under the specified exceptions in §§ 1016.13, 1016.14, or 1016.15 and does not have a change in policies or practices that would require a revised notice. This is conditional; the institution must monitor both its sharing and any changes to its privacy practices.

If the institution’s practices change

If an institution that relied on the exception changes its practices so it no longer qualifies, § 1016.5(e)(2) sets out when the institution must provide an annual notice and revised privacy notice. A customer may also receive an initial notice when the relationship begins under § 1016.4. Check the current rule for delivery timing and applicable exceptions before giving a compliance answer.

Practical application and common errors

Regulation P applies to covered financial institutions and uses “customer” differently from a consumer who has only a one-time interaction. A consumer generally becomes a customer by establishing a continuing relationship described in §1016.4(c), such as certain ongoing loan or advisory relationships. A financial institution must identify the relevant relationship and role before deciding whether an annual notice is due. State privacy laws and other federal safeguards may apply separately.

The general rule in §1016.5(a) requires an accurate, clear and conspicuous annual privacy notice at least once in each period of 12 consecutive months while the customer relationship continues. The institution may choose a consistent annual period, such as a calendar year, but must apply that method consistently. A former customer generally does not receive continuing annual notices under the federal rule.

The limited exception requires both conditions: the institution shares nonpublic personal information with nonaffiliated third parties only under the permitted exceptions in §§1016.13, .14, or .15, and its disclosed policies and practices have not changed in a way that defeats the exception. Institutions cannot claim the exception merely because they do not sell customer lists; sharing for other purposes must also be evaluated.

If the institution changes its practices so that it no longer qualifies, the timing to resume notices depends on whether a revised notice is required under §1016.8. Where no revised notice is required, §1016.5(e)(2)(ii) generally requires an annual notice within 100 days of the change. Where a revised notice is required, annual notice timing follows the applicable schedule treating that revised notice as the initial notice.

Example: a lender initially shares information only to service loans and uses an exception. It later begins sharing nonpublic information for a new purpose outside the listed exceptions. Compliance should reassess both the notice and opt-out requirements before that sharing occurs. Whether the change triggers a revised notice depends on the rule’s requirements and facts, so do not apply the 100-day timing mechanically to every policy update.

The notice exception does not erase other obligations. A financial institution may still need an initial privacy notice, honor opt-out rights when applicable, limit redisclosure and reuse, and comply with the Safeguards Rule, state privacy law, and contract requirements. Separate the annual notice question from whether a particular disclosure is permissible.

For an exam problem, identify institution coverage, consumer versus customer, whether a continuing relationship exists, what nonaffiliated disclosures occur, whether they fit the enumerated exceptions, and whether policies changed. Then select the annual-notice rule or narrow exception and its restart timing. Keep the decision documented and review it whenever data uses or vendors change.

Workflow checks and scenario

The institution should maintain a data-flow inventory that identifies each nonaffiliated recipient, information category, purpose, legal exception, and customer-facing disclosure. Vendor access for transaction processing may fit a different provision than marketing or affiliate sharing. Contract labels do not decide the legal analysis; assess what information is actually disclosed and how the recipient may use or redisclose it.

Review the annual-notice exception when onboarding a vendor, launching a marketing campaign, changing an opt-out practice, or revising a privacy statement. A customer relationship may continue even after the loan closes if servicing is retained or another continuing service remains. If a policy change removes the exception, calculate the applicable restart deadline and preserve evidence that notices were delivered.

Do not confuse the annual notice exception with an opt-out exception. Some disclosures under §§1016.14 and .15 can occur without an opt-out, while disclosures under §1016.13 may require notice and an opportunity to opt out depending on the facts. The annual exception in §1016.5(e) has its own two-part test. A privacy program should document each analysis separately instead of treating one exception as permission for every data use.

A privacy notice should accurately describe current practices rather than repeat a standard form that no longer matches vendor or marketing activity. The responsible privacy officer should coordinate changes with procurement, information security, and marketing before data sharing begins. If the institution relies on an exception, retain the written analysis and the facts supporting it. Reassess at least annually and when a product, customer relationship, or data recipient changes.

Exam takeaway

General rule: at least once in each 12-month period while the customer relationship continues. Remember the conditional exception for qualifying limited sharing with no relevant policy/practice change; do not state that annual notices are universally waived.

Common questions

Does Regulation P mean one notice every calendar year?

Not necessarily. It requires at least once in any consistent 12-consecutive-month period; the rule gives a calendar-year example.

Can every institution skip annual notices?

No. The exception depends on the institution’s information-sharing practices and whether its privacy policies changed.

Does the rule apply to every consumer?

The annual notice applies to customers during a continuing customer relationship; initial notice duties and definitions are separate.