Skip to content
LexBuild

12 CFR § 332.8 - Revised privacy notices.

---
identifier: "/us/cfr/t12/s332.8"
source: "ecfr"
legal_status: "authoritative_unofficial"
title: "12 CFR § 332.8 - Revised privacy notices."
title_number: 12
title_name: "Banks and Banking"
section_number: "332.8"
section_name: "Revised privacy notices."
chapter_name: "FEDERAL DEPOSIT INSURANCE CORPORATION"
subchapter_number: "B"
subchapter_name: "REGULATIONS AND STATEMENTS OF GENERAL POLICY"
part_number: "332"
part_name: "PRIVACY OF CONSUMER FINANCIAL INFORMATION"
positive_law: false
currency: "2026-04-05"
last_updated: "2026-04-05"
format_version: "1.1.0"
generator: "[email protected]"
authority: "12 U.S.C. 1819 (Seventh and Tenth); 15 U.S.C. 6801"
regulatory_source: "65 FR 35216, June 1, 2000, unless otherwise noted."
cfr_part: "332"
---

# 332.8 Revised privacy notices.

(a) *General rule.* Except as otherwise authorized in this part, you must not, directly or through any affiliate, disclose any nonpublic personal information about a consumer to a nonaffiliated third party other than as described in the initial notice that you provided to that consumer under § 332.4, unless:

(1) You have provided to the consumer a clear and conspicuous revised notice that accurately describes your policies and practices;

(2) You have provided to the consumer a new opt out notice;

(3) You have given the consumer a reasonable opportunity, before you disclose the information to the nonaffiliated third party, to opt out of the disclosure; and

(4) The consumer does not opt out.

(b) *Examples*—(1) Except as otherwise permitted by §§ 332.13, 332.14, and 332.15, you must provide a revised notice before you:

(i) Disclose a new category of nonpublic personal information to any nonaffiliated third party;

(ii) Disclose nonpublic personal information to a new category of nonaffiliated third party; or

(iii) Disclose nonpublic personal information about a former customer to a nonaffiliated third party, if that former customer has not had the opportunity to exercise an opt out right regarding that disclosure.

(2) A revised notice is not required if you disclose nonpublic personal information to a new nonaffiliated third party that you adequately described in your prior notice.

(c) *Delivery.* When you are required to deliver a revised privacy notice by this section, you must deliver it according to § 332.9.