skills/legal/glba-privacy-notice/SKILL.md
Drafts GLBA-compliant privacy notices using the 16 CFR Part 313 Appendix A model form safe harbor. Use when creating or updating Regulation P privacy notices, annual consumer disclosures, or NPI sharing notices for banks, credit unions, securities firms, insurers, or other covered entities under 15 U.S.C. §§ 6801–6809.
npx skillsauth add casemark/skills glba-privacy-noticeInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces a 16 CFR Part 313-compliant consumer privacy notice using the Appendix A model form safe harbor, covering mandatory disclosures, sharing categories, opt-out rights, and security safeguards.
Required model form opening:
| Field | Content | |---|---| | Why? | One-sentence explanation of why notice is provided | | What? | Categories of NPI collected (summary) | | How? | Whether and how consumers can limit sharing |
Include verbatim or substantially similar opening: "Federal law requires us to tell you how we collect, share, and protect your personal information. Federal law also gives you the right to limit some but not all sharing."
Include institution legal name, effective date, recognizable DBAs.
Group NPI by source:
| Source | Examples | |---|---| | Consumer-provided | SSN, income, assets, contact info, account preferences | | Account-generated | Balances, payment history, transactions, card activity | | Consumer reporting agencies | Credit reports/scores | | Other third parties | Identity verification, fraud databases, public records |
| Sharing Purpose | Limitable? | Authority | |---|---|---| | Everyday business (transactions, compliance, fraud) | No | §§ 313.14–.15 exceptions | | Affiliates — transaction/experience info | No | Permitted sharing | | Affiliates — creditworthiness for marketing | Yes | FCRA § 603(d)(2)(A)(iii); 30-day pre-sharing notice | | Nonaffiliates — joint marketing (formal agreement) | No | § 313.13 exception | | Nonaffiliates — their own marketing | Yes | Full GLBA opt-out |
Required affiliate marketing timing language: "If you are a new customer, we can begin sharing your information with our affiliates for their marketing purposes 30 days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice. However, you can contact us at any time to limit this sharing."
Provide all three channels (phone, online, mail) with:
Cover physical, electronic, and procedural safeguards. Include verbatim or substantially similar: "To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings."
Apply where institution operates or serves customers:
| State | Requirement | |---|---| | California | CCPA/CPRA rights; SB 1 opt-in for certain nonaffiliate sharing [VERIFY current applicability] | | Vermont | Opt-in consent before nonaffiliate marketing sharing [VERIFY current rules] | | Nevada | NRS 603A opt-out for sale of covered information [VERIFY] | | Massachusetts | 201 CMR 17.00 data security cross-reference [VERIFY] | | Insurance (NAIC) | Model Act disclosures for underwriting/claims data |
Privacy office phone, email, mailing address. Website URL for current notice. Supervisory authority (OCC, FDIC, NCUA, SEC, state insurance dept.).
Key changes from the original:
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.