Federal housing law
16 CFR § 682.3 Proper disposal of consumer information.
Title 16, Code of Federal Regulations (FTC), as enacted — this section's verbatim text. The library holds selected sections of this code, not the whole code.
- Edition
- 2026-09-25 source snapshot
- Effective
- 2005-06-01
- Last updated
- 2026-09-25
- Jurisdiction
- United States
§ 682.3¶
Proper disposal of consumer information.
(a) Standard. Any person who maintains or otherwise possesses consumer information for a business purpose must properly dispose of such information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.
(b) Examples. Reasonable measures to protect against unauthorized access to or use of consumer information in connection with its disposal include the following examples. These examples are illustrative only and are not exclusive or exhaustive methods for complying with the rule in this part.
(1) Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing consumer information so that the information cannot practicably be read or reconstructed.
(2) Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media containing consumer information so that the information cannot practicably be read or reconstructed.
(3) After due diligence, entering into and monitoring compliance with a contract with another party engaged in the business of record destruction to dispose of material, specifically identified as consumer information, in a manner consistent with this rule. In this context, due diligence could include reviewing an independent audit of the disposal company's operations and/or its compliance with this rule, obtaining information about the disposal company from several references or other reliable sources, requiring that the disposal company be certified by a recognized trade association or similar third party, reviewing and evaluating the disposal company's information security policies or procedures, or taking other appropriate measures to determine the competency and integrity of the potential disposal company.
(4) For persons or entities who maintain or otherwise possess consumer information through their provision of services directly to a person subject to this part, implementing and monitoring compliance with policies and procedures that protect against unauthorized or unintentional disposal of consumer information, and disposing of such information in accordance with examples (b)(1) and (2) of this section.
(5) For persons subject to the Gramm-Leach-Bliley Act, 15 U.S.C. 6081 et seq., and the Federal Trade Commission's Standards for Safeguarding Customer Information, 16 CFR part 314 (“Safeguards Rule”), incorporating the proper disposal of consumer information as required by this rule into the information security program required by the Safeguards Rule.
Part authority and source: Pub. L. 108-159, sec. 216; 69 FR 68697, November 24, 2004.
Official source: 16 CFR § 682.3 Proper disposal of consumer information..
Source snapshot retrieved: 2026-09-25T21:59:08.932832+00:00.
eCFR currency: Title 16 is up to date as of 2026-09-24.
Version dates (indexing metadata): Effective 2005-06-01; operative 2005-06-01.
Date evidence (16 CFR 682.5, part-wide): The rule in this part is effective on June 1, 2005.
Evidence source: https://www.ecfr.gov/current/title-16/section-682.5
Applicability note (indexing metadata, not regulatory text): Apply the consumer-information definitions and Federal Trade Commission jurisdiction limits in sections 682.1 and 682.2. Disposal safeguards are reasonable measures, and the examples in section 682.3 are illustrative and nonexhaustive. Section 682.4 preserves other legal record-retention and destruction requirements; this rule does not set a universal retention period. The part-wide effective date in section 682.5 is also the operative date; the captured part contains no separate delayed operative provision. This current-source capture alone does not establish every historical version.