{"data":{"id":"us/12-cfr-1008.305","jurisdiction":"us","citation":"12 CFR 1008.305","heading":"Data security.","body":"(a) To the extent that CSBS, AARMR, or their successors maintain the NMLSR, CSBS, AARMR, and their successors, as applicable, must complete a background check on their employees, contractors, or other persons who have access to loan originators' Social Security Numbers, fingerprints, or any credit reports collected by the system.\n(b) To the extent that CSBS, AARMR, or their successors maintain the NMLSR, CSBS, AARMR, and their successors as applicable, must keep and adhere to an appropriate information security and privacy policy. If the NMLSR forms a reasonable belief that a security breach has occurred, it shall notify affected parties, as soon as practicable, including the Bureau, any loan originator or registrant whose data may have been compromised, and the employer of the loan originator or registrant, if such employer is also licensed through the system.","path":["Title 12—Banks and Banking","CHAPTER X—CONSUMER FINANCIAL PROTECTION BUREAU","PART 1008—S.A.F.E. MORTGAGE LICENSING ACT—STATE COMPLIANCE AND BUREAU REGISTRATION SYSTEM (REGULATION H)","Subpart D—Minimum Requirements for Administration of the NMLSR"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-12.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:24:16Z","sha256":"07464e766bd5f08ba28154b8f38ef97d75d478e7e393fe445d0147c46b0ea0af","source_id":"us-cfr","stale":true,"prev":"us/12-cfr-1008.303","next":"us/12-cfr-1008.307"},"notice":"GroundRules: Original legal text. Not legal advice."}
