All licensees shall create and maintain an information security program to safeguard the nonpublic personal information of customers to the extent required by 16 C.F.R. Part 314 (the "Safeguards Rule"). As part of its regulatory oversight, the Department shall review, to the extent applicable, licensee's information security programs, risk assessments, incident response plans, and other required elements of the Safeguards Rule.
Ga. Comp. R. & Regs. R. 80-14-1-.06
O.C.G.A. §§ 7-1-61, 7-3-51.