R649, Utah Higher Education Assistance Authority Privacy Policy

R649-1. Purpose: The purpose of this rule is to provide the terms of UHEAA’s privacy policy concerning the disclosure of customer nonpublic personal information, as defined in the Gramm-Leach-Bliley Act, referenced below.

R649-2. References

2.1. Utah Code Title 53B, Utah System of Higher Education, Chapter 12.

2.2. S. Code, Title IV of the Higher Education Act of 1965, as amended.

2.3. S. Federal Trade Commission, Code of Federal Regulations, 16 CFR Part 313.

2.4. L. No. 106-102, the Gramm-Leach-Bliley Act

R649-3. General

3.1. Personal Information Collected: UHEAA collects nonpublic personal information about customers from:

3.1.1. information received from customers on applications or other forms;

3.1.2. information from customer transactions with UHEAA, its affiliates or others; and

3.1.3. information received from a consumer reporting agency.

3.2. No Disclosure Except as Permitted by Law: UHEAA does not disclose any nonpublic personal information about our customers or former customers to anyone, except as permitted by law.

3.3. Access Restrictions and Safeguards: UHEAA restricts access to nonpublic personal information about customers to those employees who need to know such information to provide products or services to customers. UHEAA maintains physical, electronic, and procedural safeguards that comply with federal regulations to guard customer nonpublic personal information.

Adopted by the UHEAA Board of Directors April 10, 2001.