BREWERY CREDIT UNION PRIVACY POLICY
PURPOSE OF THIS POLICY
The purpose of this policy is to insure Brewery Credit Union ("BCU") complies with existing federal and state laws with respect to the privacy and security of member's nonpublic personal information.
GENERAL PROVISIONS
BCU shall protect the confidentiality, security, and integrity of each member's nonpublic personal information in accordance with existing state and federal laws.
The credit union will maintain physical, electronic, and procedural safeguards that comply with federal standards to guard members' nonpublic personal information.
The credit union will not gather, collect, or maintain any information about its members that is not necessary in order to offer its products and services, to complete member transactions or for other relevant business purposes.
The credit union does not, and will not, sell or provide any member information to third parties including list services, telemarketing firms, or outside companies for independent use.
INFORMATION SECURITY PROGRAM
Management of BCU shall be responsible for developing, implementing, and maintaining an effective information security program to: (1) insure the security and confidentiality of member records and information; (2) protect against any anticipated threats or hazards to the security or integrity of such records; and (3) protect against unauthorized access to or use of such records or information that would result in substantial harm or inconvenience to any member.
Management shall regularly (no less than annually) report to the board on the current status of the credit union's information security program.
ASSESSMENT OF RISK
In order to assess the risks that may threaten the security, confidentiality, or integrity of member information or member information systems, the credit union shall:
- Identify all reasonably foreseeable internal as well as external threats that can result in unauthorized disclosure, misuse, alteration, or destruction of member information or member information systems.
- Determine the likelihood as well as potential damage for the internal and external threats.
- Determine the sufficiency of the credit union's policies, procedures and member information systems to control the identified risks.
Next Page |