The act mandates financial institutions that obtain nonpublic personal information through the normal course of their business must develop precautions to ensure the security and confidentiality of customer records and information, and protect against unauthorized access to, or use of such records. This includes secure storage, disposal, and sharing of confidential information.

