> Data Destruction Topics > Media Sanitization Scenarios
Fair and Accurate Credit Transactions Act of 2003 [FACTA] DISPOSAL RULE ONLY
STATUS: Disposal Rule in effect June 1, 2005
FULL NAME: Fair and Accurate Credit Transactions Act of 2003
TARGET: Individuals or organizations of any kind who use consumer reports, including: consumer reporting companies, lenders, insurers, employers, landlords, government agencies, mortgage brokers, car dealers; attorneys; private investigators; debt collectors; individuals who pull consumer reports on prospective home employees, such as nannies or contractors; and entities that maintain information in consumer reports as part of their role as a service provider to other organizations covered by the Rule.
The Rule covers information in both electronic and hard copy form.
DESCRIPTION: The Act itself actually directs other agencies (see below) to adopt consistent and comparable rules regarding the proper
disposal of consumer report information and records. These rules must also be consistent with the requirements of the Gramm-Leach-Bliley Act.
AGENCIES: FACTA directs the FTC, the Federal Reserve Board, the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the Office of Thrift Supervision, the National Credit Union Administration, and the Securities and Exchange Commission to adopt comparable and consistent rules regarding the disposal of sensitive consumer report information.
DATA SECURITY FACTORS:: The final Rule includes several examples of "reasonable measures", to protect consumer information in
connection with its disposal. Among the scenarios specified in the Federal Rules and Regulations is destruction or purging of electronic media in accordance with methods specified in NIST Special Publication 800-88: Guidelines for Media Sanitation.
EXCEPTION FOR SERVICE PROVIDERS: Service providers are liable for violations of the Rule only
if the service providerhas been notified that the information it possesses is consumer
information as defined in the Rule; and has entered into a written contract to dispose of
such information in accordance with this Rule. However, Under the final Rule, service providers continue to be covered, and, therefore, along with the record owner, bear responsibility for proper disposal of consumer information that they maintain or otherwise possess.
Complete listing and links for data security regulations and legislation.