Sitonce
Country: HK
Show exams for United States Hong Kong
Sign in

Sharing consumer information with a service provider

Updated 5 min read
Key takeaway

Regulation P permits a financial institution to disclose nonpublic personal information to a nonaffiliated service provider or for qualifying joint marketing without giving the consumer an opt-out when the institution gives the required initial notice and has a contract limiting the recipient's use and redisclosure of the information to the permitted purposes.

On this page11 sections
  1. The two core conditions
  2. What counts as covered sharing
  3. The initial notice still matters
  4. Do not mix this with transaction-processing exceptions
  5. Exam decision path
  6. Key takeaway
  7. The exception permits a defined disclosure without an opt-out
  8. Service provider versus joint marketer
  9. A practical decision path
  10. Exam traps and controls
  11. Additional boundary detail

The Gramm-Leach-Bliley Act privacy rule generally gives consumers an opportunity to opt out before a financial institution discloses nonpublic personal information to most nonaffiliated third parties. Regulation P contains exceptions. The service-provider and joint-marketing exception allows some sharing without an opt-out, but it has conditions; calling a vendor a service provider does not automatically qualify the disclosure.

The two core conditions

  1. The institution must provide the consumer with the initial privacy notice required under Regulation P.
  2. The institution must enter into a contract with the service provider or joint marketer that prohibits the recipient from disclosing or using the information except to carry out the purposes for which the institution disclosed it, including use under the joint-marketing agreement where applicable.

The contract condition is a use-and-redisclosure limit. A contract that merely states the vendor will protect information, but allows independent marketing or unrelated reuse, may fail to capture the required restriction. The institution should define the permitted purpose and ensure the contractual controls match it.

What counts as covered sharing

The exception concerns nonpublic personal information disclosed to a nonaffiliated third party acting as a service provider or a financial institution with which the institution has a joint-marketing agreement. The information must be used to perform the services or marketing covered by the exception. The recipient's own later disclosure is separately constrained by Regulation P's redisclosure and reuse rules.

The initial notice still matters

The exception removes the requirement to provide an opt-out for that qualifying disclosure; it does not erase the initial privacy-notice requirement. The institution must still describe its practices under the applicable notice rules. Other notice duties can apply depending on the relationship and the institution's information-sharing practices.

Do not mix this with transaction-processing exceptions

Regulation P separately permits some disclosures needed to process or service a transaction, and other disclosures such as those required or authorized by law. Those exceptions can have different notice and opt-out treatment. First identify the purpose: outsourced servicing, joint marketing, transaction processing, legal compliance or another permitted reason. Then use the specific section that covers it.

Exam decision path

  1. Is the information nonpublic personal information about a consumer within the rule's scope?
  2. Is the recipient nonaffiliated and acting as a qualifying service provider or joint marketer?
  3. Has the financial institution delivered the required initial privacy notice?
  4. Does a written contract limit use and redisclosure to the permitted purpose?
  5. If any required condition is missing, do not assume the opt-out exception applies; analyze the default rule and any other exception.

Key takeaway

For the service-provider or joint-marketing exception, remember notice plus a restrictive contract. The vendor relationship alone is not enough, and this exception does not convert every third-party disclosure into permitted sharing.

The exception permits a defined disclosure without an opt-out

Regulation P generally gives consumers notice and an opportunity to opt out before a financial institution discloses nonpublic personal information to a nonaffiliated third party. Section 1016.13 creates a service-provider and joint-marketing exception, but it is conditional. The institution must provide the required initial privacy notice and have a contract with the recipient that limits the recipient’s use and redisclosure of the information.

The contract must restrict use to performing the services for which the information was disclosed, or carrying out the joint-marketing arrangement, and restrict disclosure or use in other ways the rule specifies. A vendor relationship by itself is not enough. Identify the recipient, information, service, contract, and permitted purpose before relying on the exception.

Service provider versus joint marketer

A service provider performs services for the financial institution, such as processing or servicing. Joint marketing is a written agreement between a financial institution and one or more other financial institutions to jointly offer, endorse, or sponsor a financial product or service. A general referral arrangement, data sale, or unrelated advertising campaign should not automatically be described as joint marketing.

Confirm the recipient is a qualifying nonaffiliated financial institution when relying on the joint-marketing branch. For a service provider, make sure the contract’s privacy provisions fit the activity and the recipient receives only the information it needs. If the vendor wants to use the data for its own independent marketing, that use may exceed the exception.

A practical decision path

First determine whether the information is nonpublic personal information and whether the recipient is affiliated. Next identify the applicable disclosure rule and exception. Then check that the initial privacy notice was delivered as required, the written contract imposes the required limits, and the actual data flow matches the stated purpose. Finally, check whether another law, contract, or security rule imposes additional safeguards.

Example: a servicer sends account information to a contracted payment processor so it can post borrower payments. That use may fit the service-provider exception if the notice and contract conditions are satisfied. If the processor reuses the information to market unrelated credit products, the institution should not assume the original processing exception covers the new purpose.

Exam traps and controls

The service-provider exception does not erase the privacy notice requirement; it can eliminate the consumer opt-out for the specified disclosure when the conditions are met. Nor does it authorize unlimited reuse by the recipient. Section 1016.11 separately limits reuse and redisclosure of information received under an exception.

Maintain a vendor inventory, contract clause review, data-flow map, and periodic test of actual vendor use. Route proposed new uses through privacy review before a vendor changes its product or analytics. On an exam, name both prerequisites—initial notice and a qualifying contract—and then state the purpose limitation.

Additional boundary detail

Contract review should cover subcontractors and onward transfers, not just the named vendor. If a processor uses a cloud host or analytics vendor, determine whether that access is necessary to perform the contracted service and whether the same restrictions flow downstream. Keep the information set proportionate to the job. When the vendor proposes a new product feature or a different use, reassess the exception before data are reused.

Common questions

Can a mortgage lender share information with a service provider without an opt-out?

Potentially, if the Regulation P conditions are met, including the required initial notice and a contract restricting use and redisclosure to the permitted purpose.

Does the service-provider exception eliminate privacy notices?

No. The institution must still provide the initial privacy notice required by the rule.

Can the service provider use the information for its own unrelated advertising?

The required contract must restrict the recipient from using or disclosing the information except to carry out the purposes for which it was disclosed, subject to the rule's terms.