Section 63.06. Confidentiality and security requirements.  


Latest version.
  • No credit union may directly or indirectly acquire, place or operate a remote terminal, and no credit union may participate in the acquisition, placement or operation of a remote terminal, unless precautions acceptable to the director are provided to:
    (1) Precautions against unauthorized access. Prevent unauthorized access to, or use of, the terminal.
    (2) Precautions to assure confidentiality. Prevent information regarding a transaction conducted through the terminal from being disclosed to any person other than:
    (a) The customer making the transaction;
    (b) Any other person who is a party to the transaction or is necessary to effect the transaction, but only to the extent that the information disclosed is necessary to effect the transaction; or
    (c) Those persons lawfully authorized to have access to the records of the credit union or of parties to the transaction.
    (3) Unsolicited access to remote terminals prohibited. Ensure that the plastic card or other means providing its customers access to the terminal is issued only:
    (a) In response to a request or application therefore; or
    (b) As a renewal of, or in substitution for an accepted card or other means of access, whether issued by the initial issuer or a successor.