Privacy actions
| Right | What it can do | Important limit |
|---|---|---|
| Access / know | Ask what personal information is collected or maintained where the right applies. | Verify identity before releasing sensitive information. |
| Delete | Ask for deletion where the right applies. | Legal, fraud, security, contract and financial-information exceptions may require retention. |
| Correct | Ask to correct inaccurate personal information. | Route credit-report inaccuracies to the relevant reporting company/furnisher when CTCLoans does not control the data. |
| Opt out | Stop covered sale/share or targeted-advertising uses where applicable. | Connect the preference to the actual advertising/data-sharing systems. |
| Limit sensitive PI | Request applicable limits on sensitive personal information. | Do not offer this control unless it maps to implemented data practices and applicable law. |
| Appeal | Challenge a denied privacy request where applicable law provides an appeal. | Give a clear explanation and next channel. |
Financial-data exceptions can change the answer
Some personal information handled in connection with financial products or services may fall under GLBA/FCRA or other exemptions that change how a state privacy right applies. A denial or limitation should explain the applicable reason rather than pretending the information does not exist.
How a privacy request should work
- Choose the requested right.
- Provide only the information needed to identify the relevant CTCLoans record.
- Complete reasonable verification when required.
- Receive confirmation and an expected response path.
- If the request is denied or limited, receive the reason and any applicable appeal method.
Authorized agents
Where law permits an authorized agent to make a request, CTCLoans may need evidence of the agent’s authority and may still verify the consumer directly when permitted.