Learn About The Law
Get help with your legal needs
FindLaw’s Learn About the Law features thousands of informational articles to help you understand your options. And if you’re ready to hire an attorney, find one in your area who can help.
Current as of January 02, 2025 | Updated by Findlaw Staff
(a) In general. Any covered affiliate must adopt must adopt reasonable, written policies and procedures that address administrative, technical, and physical safeguards for the protection of consumer information. These written policies and procedures must be reasonably designed to:
(1) Insure the security and confidentiality of consumer information;
(2) Protect against any anticipated threats or hazards to the security or integrity of consumer information; and
(3) Protect against unauthorized access to or use of consumer information that could result in substantial harm or inconvenience to any consumer.
(b) Standard. Any covered affiliate under this part who maintains or otherwise possesses consumer information for a business purpose must properly dispose of such information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.
(c) Examples. The following examples are “reasonable” disposal measures for the purposes of this subpart—
(1) Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing consumer information so that the information cannot practicably be read or reconstructed;
(2) Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media containing consumer information so that the information cannot practically be read or reconstructed; and
(3) After due diligence, entering into and monitoring compliance with a written contract with another party engaged in the business of record destruction to dispose of consumer information in a manner that is consistent with this rule.
(d) Relation to other laws. Nothing in this section shall be construed:
(1) To require a person to maintain or destroy any record pertaining to a consumer that is imposed under Sec. 1.31 or any other provision of law; or
(2) To alter or affect any requirement imposed under any other provision of law to maintain or destroy such a record.
Cite this article: FindLaw.com - Code of Federal Regulations Title 17. Commodity and Securities Exchanges § 17.162.21 Proper disposal of consumer information - last updated January 02, 2025 | https://codes.findlaw.com/cfr/title-17-commodity-and-securities-exchanges/cfr-sect-17-162-21/
FindLaw Codes may not reflect the most recent version of the law in your jurisdiction. Please verify the status of the code you are researching with the state legislature before relying on it for your legal needs.
A free source of state and federal court opinions, state laws, and the United States Code. For more information about the legal concepts addressed by these cases and statutes, visit FindLaw’s Learn About the Law.
Get help with your legal needs
FindLaw’s Learn About the Law features thousands of informational articles to help you understand your options. And if you’re ready to hire an attorney, find one in your area who can help.
Search our directory by legal issue
Enter information in one or both fields (Required)