What it means
The rule covers nonpublic personal information, which means details that a customer gives to an institution or that the institution collects while providing a service. Examples are income, account balances, payment history and the fact that someone is a customer at all.
Public information, such as an address that appears in a phone directory, is generally treated differently. A financial institution must give each customer a privacy notice when the relationship starts.
The notice explains what information is collected, with whom it is shared and how it is protected. Under a later change in the law, annual notices can be skipped if the institution shares information only in ways that do not trigger opt-out rights and its practices have not changed.
When an institution wants to share nonpublic personal information with an unaffiliated third party, it generally must give the customer a reasonable chance to opt out before doing so. The opt-out is the customer's right to say no to the sharing.
There are exceptions for sharing needed to process transactions, service accounts or meet legal obligations. The rule is written and enforced mainly by the Consumer Financial Protection Bureau for most institutions, with other agencies handling particular sectors such as securities firms.
Many states add their own stricter privacy rules, and institutions that operate in several states often apply the strictest standard everywhere. It also sits beside separate rules on data security that require safeguards for customer information.
For non-finance professionals, the lesson is that sharing customer data is not a free marketing resource in a financial business. A fintech selling leads to partners, or a bank cross-selling insurance, must check that the sharing is disclosed and that the opt-out choices are honoured.
A breach of the rules can lead to enforcement and reputational damage. A good way to apply the rule is to treat each new data-sharing idea as a small project with a checklist.
Does the sharing involve an unaffiliated party, is it covered by an exception, does the current notice describe it accurately and is there a working opt-out process? Answering these questions early is much cheaper than rewriting notices after a complaint.
In practice
Real-world examples.
Example
A customer opens a new savings account and receives a privacy notice explaining the bank's sharing practices. The notice says the bank shares information with affiliates for servicing but not with outside marketers, so no opt-out is needed.
Example
A lender wants to share a list of its borrowers with a partner firm that sells home insurance. Before it can do so, the lender must send the borrowers a notice and give them a reasonable time to opt out.
Example
A fintech app sends customer data to a payment processor so that it can complete card transactions. This type of sharing falls within an exception for processing, so no opt-out choice is required.
Case study
Seen in the real world.
Larkspur Finance is an illustrative, fictional online lender. Its marketing director proposed sharing customer contact lists with a partner that sold budgeting software, expecting a healthy referral fee for every customer who signed up.
The compliance officer pointed out that the lender's existing privacy notice said it did not share information with outside marketers. Larkspur revised the notice, gave customers a clear opt-out with a reasonable period to respond, and excluded anyone who objected. The partnership launched a month later with fewer names than originally planned. The illustrative lesson is that privacy promises are commitments, and changing them takes process as well as intent.
Larkspur also added the privacy check to its launch checklist for every new product, so future partnerships were assessed before they reached customers. The marketing team found that the checklist saved time because disputes arose less often.
Watch out
Common mistakes.
- Treating the notice as a formality, when the statements in it must match what the institution actually does with customer information.
- Believing that opt-out is needed for every kind of sharing, when exceptions cover processing, servicing and legal requirements.
- Assuming the rule is the only privacy law that applies, when state laws and separate data security rules may also apply.
Questions
People also ask.
Who is covered by Regulation P?
Financial institutions as defined in the law, which include banks, lenders, insurers and other firms significantly engaged in financial activities.
What is the difference between a customer and a consumer?
A customer has a continuing relationship with the institution, while a consumer may only have applied for a product or made a one-off transaction.
Can a customer stop all sharing?
Not entirely, because the opt-out right covers sharing with unaffiliated third parties and does not apply to the exceptions for processing and legal compliance.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
