12 CFR 1008.305
§ 1008.305 Data security.
United States · 12 CFR — Banks and Banking · Status: effective
Cite this
- Citation
- 12 CFR 1008.305, § 1008.305 Data security, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/49305
- Permanent ID
ys:prov:49305@1- SHA-256
e3ecdcc5f5eeb58f2c8026666e6482f240e84b88c6e3b6ccdc3d814c37a5672e
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) To the extent that CSBS, AARMR, or their successors maintain the NMLSR, CSBS, AARMR, and their successors, as applicable, must complete a background check on their employees, contractors, or other persons who have access to loan originators' Social Security Numbers, fingerprints, or any credit reports collected by the system.
(b) To the extent that CSBS, AARMR, or their successors maintain the NMLSR, CSBS, AARMR, and their successors as applicable, must keep and adhere to an appropriate information security and privacy policy. If the NMLSR forms a reasonable belief that a security breach has occurred, it shall notify affected parties, as soon as practicable, including the Bureau, any loan originator or registrant whose data may have been compromised, and the employer of the loan originator or registrant, if such employer is also licensed through the system.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.