Transfer Agent Online Privacy and Security
In Global Fund Services’ capacity as transfer agent and a covered institution under Regulation S-P (Reg S-P), we developed and implemented a written Reg S-P Program (Program) to meet the requirements of Reg S-P. In Global Fund Services capacity as a service provider, we are mindful of our clients’ privacy obligations to their investors under Reg S-P. Accordingly, pursuant to its transfer agency or investor recordkeeping agreements with its clients, Global Fund Services keeps all records and other information relative to investors confidential and will not use this information other than for purposes of fulfilling its transfer agent or investor recordkeeping duties, except when requested to divulge such information by duly constituted authorities or court process, or when requested by an investor or an investor’s agent.
We will collect the following Nonpublic Personal Information from current and prospective customers/investors on behalf of its clients:
- Information concerning identity such as name, address, date of birth and social security number;
- Information about current and historical financial transactions;
- Information on applications including beneficiary and bank information;
- Information received on other documents, through data transmissions, email, facsimile or by telephonic device which may include all the above Nonpublic Personal Information.
This information is collected by employees in their normal course of employment with U.S. Bank. All services agent employees may have some type of access to Nonpublic Personal Information.
We have controls to ensure compliance with Reg S-P and to prevent any unauthorized access, use or dissemination of Nonpublic Personal Information. These controls include, but are not limited to:
- All employees must be fingerprinted.
- All employees complete online Information Security Awareness training, which requires a passing grade on the course assessment, and receive ongoing training to reinforce the importance of data privacy.
- Duties are segregated among personnel, including any quality control checks completed on a sample basis of incoming and outgoing non-public personal information and customer information entered into customer information systems.
- Verify the authenticity of customers by requiring customers to provide certain pieces of non-public personal information to prevent unauthorized access.
- Require unique logon IDs and passwords. All computers, mobile devices and storage media must be password protected, employees are not to share passwords with anyone, and employees are to make passwords difficult to guess or predict. User access to each application is controlled and monitored by standardized procedures, including:
- Terminated or transferred employees have access to applicable applications removed in a timely manner
- Users are assigned unique preferred IDs
- Passwords follow appropriate standards.
- On a quarterly basis, audits are conducted to determine whether changes to user access were made in accordance with procedures.
- When sending confidential or personal information, employees are to know who they are sending information to and to make sure that the receiver is authorized to receive the information. All electronic data transmissions containing non-public personal information are encrypted.
- Employees are not to leave confidential or personal information on desks unattended. Mobile devices (laptops, tablets, mini portable desktops, etc.) containing confidential or personal information must be secured when unattended. Computers are password-protected when an employee leaves their desk.
- Mobile devices must be encrypted, must have a password-protected feature enabled. Employees are discouraged from placing any confidential or personal information on a personally owned device; devices owned by the company must be configured according to bank standards. Employees connecting to bank systems using a wireless connection must do so through an authorized USB VPN Portal. Any lost or stolen device must be reported to the USB Privacy Office immediately.
For privacy related information, please visit usbank.com/privacy. For California related privacy requests, please visit the U.S. Bank California Privacy Center or call our toll-free phone number 1-800-872-2657.