Credit unions can now ignore official guidance on protecting customer data
What happened
The US credit union regulator is removing its official guidelines for how credit unions must protect customer information. These guidelines will now be published as an informal letter, which means they are no longer part of the official rulebook.
Why it matters
For years, credit unions had clear, official guidance on how to safeguard member data, even if it was only a guideline. Now, that guidance is gone from the official rulebook. This means credit unions have more flexibility, but also less clarity, on what constitutes sufficient data protection.
The signal
Watch for any increase in data breaches reported by credit unions, or new, more specific rules from the regulator if data protection becomes a bigger problem.