The Federal Trade Commission has issued a final rule under the Gramm-Leach-Bliley Act which will require private equity firms with individual and IRA investors to develop and implement a written "information security program" appropriate to their operations by May 23, 2003. The rule sets forth standards for "developing, implementing and maintaining reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of customer [i.e., individuals’ and IRA investors’] information." In addition, certain contracts with service providers who handle a private equity firm’s nonpublic personal customer information may also need to be amended by May 23, 2003 to provide for the safeguarding of this information. As covered in prior editions of Venture Update and TH&T client bulletins, the Gramm-Leach-Bliley Act also requires private equity firms with individual and IRA investors to send annual privacy notices to these customers covering the use of their nonpublic personal information.
The content of this article does not constitute legal advice and should not be relied on in that way. Specific advice should be sought about your specific circumstances.