AZ Circular Letter 2000-12
AZ Circular Letter 2000-12: Enforcement of Gramm-Leach-Bliley Privacy Requirements
STATE OF ARIZONA
DEPARTMENT OF INSURANCE
JANE DEE HULL
2910 NORTH 44th STREET, SUITE 210
CHARLES R. COHEN
Governor
PHOENIX, ARIZONA 85018-7256
Director of Insurance
602/912-8456 (phone) 602/912-8452 (fax)
Circular Letter 2000-12
TO:
Insurance Industry Representatives; Insurance Trade Associations; and
Other Interested Parties
FROM:
Charles R. Cohen
Director of Insurance
DATE:
October 3, 2000
RE:
Enforcement of Gramm-Leach-Bliley Privacy Requirements
The Gramm Leach Bliley Act, Public Law 106-102, November 12, 1999 (“GLB”) requires
financial institutions, including insurers, to protect the privacy of consumers’ non-public
personal information. Title V of GLB requires federal and state regulators to implement
GLB’s privacy protections within 6 months of the bill’s effective date, except to the
extent that a later date is specified in rule. (See GLB §§ 504 and 510(1).) The Act and
its implementing regulations take effect on November 13, 2000. Under the authority of
GLB § 510(1) federal regulators have elected to delay enforcement until July 1, 2001.
(See 65 Fed. Reg. 35162, 35184-35185 (June 1, 2000).)
The delayed enforcement date will give federally regulated financial institutions
sufficient time to establish policies, procedures, and systems required to comply with
the new federal requirements. In deciding to delay enforcement, federal regulators
noted that “financial institutions are expected…to begin compliance efforts promptly, to
use the period prior to June 30, 2001 to implement and test their systems, and to be in
full compliance by July 1, 2001.” (Id. p. 35185.)
GLB gives state insurance regulators authority to enforce federal privacy laws, as they
apply to insurers. GLB § 505(a)(6). Subject to GLB’s nondiscrimination standards and
other preemption provisions, states may enact and enforce privacy standards that
exceed those in GLB. GLB § 507
ne 30, 2001 to implement and test their systems, and to be in
full compliance by July 1, 2001.” (Id. p. 35185.)
GLB gives state insurance regulators authority to enforce federal privacy laws, as they
apply to insurers. GLB § 505(a)(6). Subject to GLB’s nondiscrimination standards and
other preemption provisions, states may enact and enforce privacy standards that
exceed those in GLB. GLB § 507. If a state fails to adopt regulations that meet at least
the federal minimum standards, the state will lose its enforcement authority. GLB §
505(c).
Arizona already regulates privacy of consumers’ personal information. The Arizona
Insurance Information and Privacy Protection Act, A.R.S. § 20-2101et seq., protects
Circular Letter 2000-12
October 3, 2000
Page 2
“individually identifiable information gathered in connection with an insurance
transaction and from which judgments can be made about an individual’s character,
habits, avocations, finances, occupation, general reputation, credit, health or any other
personal characteristics, including medical record information. See A.R.S. § 20-
2102(18). Arizona’s privacy law (which is based on a 1980 NAIC model law) is, in most
respects, more comprehensive and more stringent than GLB standards. Insurers doing
business in Arizona have complied with this law since the early 1980’s. The
Department intends to propose legislation in the 2001 session amending this law to
ensure that all Arizona standards are at least as stringent as federal minimum
standards.
The Department is issuing this circular to advise insurers and other interested parties of
its policy for enforcement of GLB’s privacy standards.
• ADOI has no discretion to waive or defer compliance with current state law A.R.S. §
20-2101 et seq.) and will enforce this statute as it has been enforced since
enactment
hat all Arizona standards are at least as stringent as federal minimum
standards.
The Department is issuing this circular to advise insurers and other interested parties of
its policy for enforcement of GLB’s privacy standards.
• ADOI has no discretion to waive or defer compliance with current state law A.R.S. §
20-2101 et seq.) and will enforce this statute as it has been enforced since
enactment.
• To the extent that any new standards are adopted in the 2001 session, they will not
be effective until the regular effective date for 2001 legislation (90 days sine die),
which will almost certainly be later than the federal compliance date of July 1, 2001.
If an earlier effective date is required and the legislation passes as an emergency
measure, the Department will support a delayed enforcement date of July 1, 2001.
• To the extent that the Department has authority to enforce federal privacy standards
that are not part of A.R.S. Title 20, the Department will act in accordance with the
delayed enforcement date (July 1, 2001) adopted by federal regulators.
Like the federal regulators, it is the Department’s expectation that insurers will use the
time between now and July 1, 2001 to ready their systems for full compliance with
privacy requirements.
Please direct any questions regarding this circular letter to Vista Thompson Brown,
Executive Assistant for Policy Affairs, 602-912-8456.