Will New GDPR Rule Impact Your CU?

By Ray Birch

WASHINGTON—The European Union’s General Data Protection Regulation (GDPR) rule will likely have credit unions evaluating just how many members they have in the E.U., while they also need to be talking with vendors about the new law.

The E.U.’s General Data Protection Regulation became effective May 25.

The regulation, which purports to apply to companies anywhere in the world with customers or members living in the E.U., contains provisions and requirements pertaining to the processing of personally identifiable information of individuals. These regulations could potentially apply to U.S. entities that process the personal data of E.U. residents when offering them goods and services, sources say.

Lance Noggle, CUNA senior director of advocacy over payments and cybersecurity, and senior counsel, told CUToday.info that credit unions will have to pay attention to the GDPR, but a lot still needs to be determined as to the extent CUs could be impacted.

“We will have to see how this shakes out,” said Noggle.

Noggle pointed out that even credit unions of modest size will likely have some members living in the E.U.

“And the numbers would be higher for credit unions that serve the military or the State Department, for example,” he said. “This law is aimed at large companies that serve large numbers of European Union residents, not small community banks and credit unions in the U.S. However, it’s possible the rule could be enforced against CUs here. But again, we are not sure how or if this rule will be enforced on smaller U.S. companies.”

Key Compliance Requirements

Noggle explained that the key compliance requirements under the GDPR include:

  • Business accountability measures that include data protections officers, record maintenance requirements, privacy impact assessments, privacy by design and default for all data collection systems, privacy policies, controller and processor responsibilities, restrictions on transfers to third countries, proof of compliance and mandatory appointment of a data protection officer in certain circumstances
  • Requiring notification of a data breach to a supervisory authority within 72 hours (subject to conditions) and notification to affected data subjects without undue delay (with certain exceptions
  • Demonstration of consent in a clear, intelligible manner, with the right to withdraw consent by the data consent. Existing consents may not be valid
  • Defined consumer rights that include disclosure of data collection, right to access to records and purpose of data collection, right to restrict processing, right to recertification and erasure, right to data portability, right to lodge a complaint, right to legal remedies, right to object to profiling and penalties for violations
FTC

Which Laws Will Govern?

While there is no express civil enforcement mechanism in the GDPR itself, international law will govern the enforcement of any civil penalty. The Federal Trade Commission indicated in the adequacy determination that it will use Unfair and Deceptive Practices to enforce penalties, but there is no rule expressly mandating compliance with the GDPR.  Therefore, how, if at all, these provisions will be enforced against U.S. credit unions will be determined over time, Noggle explained.  

Noggle said that credit unions are already having discussions with some of their vendors that are involved with handling personally identifiable information of individuals with the CU.

“Some vendors are asking if credit unions are GDPR compliant,” said Noggle. “You will probably see more credit unions having discussions with vendors that either want them to take on all liability for any GDPR violation or asking them to become GDPR compliant.”

What to Do?

With uncertainty surrounding the GDPR’s impact on credit unions, what should the movement do?

“The first thing credit unions should do is assess how many members they have living in the E.U.,” advised Noggle. “Know what your exposure is. That could help you make a decision as to your liability around the GDPR.”

Noggle said that some time needs to pass to see how the E.U. applies the GDPR to U.S. companies, the size of any companies the E.U. takes action on, and how the rule is enforced.

Noggle believes more credit union time will be spent with vendors who will want the CU to become GDPR compliant or agree to accept liability for any GDPR enforcement against the vendor.

“A lot of wait and see here,” he said.

CUNA recently held a webinar on the topic and Noggle said that the trade association is planning a second webinar.

Section: Standard
Word Count: 891
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Will-New-GDPR-Rule-Impact-Your-CU