Skip to main content
Category: Regulatory & Privacy Compliance

Consumer Privacy Protection Model Act

Also known as: Insurance Consumer Privacy Protection Model Law #674, Model #674, Consumer Privacy Protection Model Law
Simply put

The Consumer Privacy Protection Model Act (Model #674) was a draft model law developed within the National Association of Insurance Commissioners (NAIC) that proposed standards for how insurance licensees, including insurers, agents, and brokers, collect, process, retain, and share consumers' personal information. It was intended as a template that individual states could adopt into their own insurance laws. This draft was not adopted: the relevant NAIC working group decided in 2024 to set the draft aside and instead revise an existing model (the Privacy of Consumer Financial and Health Information Regulation, Model #672), so #674 is no longer an active project.

Formal definition

Model #674 was an exposure draft advanced by the NAIC Privacy Protections (H) Working Group that would have established consumer data privacy standards specific to the business of insurance, governing the collection, processing, retention, and sharing of consumers' personal information by licensees such as insurers, agents, and brokers. As an NAIC model law, it had no direct legal force; it would have required enactment or adoption by individual state legislatures or insurance regulators to become binding, with substance potentially varying by jurisdiction. On June 12, 2024, the working group voted to set aside the #674 draft in favor of revising the pre-existing Privacy of Consumer Financial and Health Information Regulation (Model #672, originally adopted in 2000 and last amended in 2017). As of this writing, #674 is not an active NAIC project and should be treated as a superseded/abandoned draft rather than a forthcoming standard. This entry addresses insurance-sector privacy regulation and is distinct from general state consumer data privacy statutes and from U.S. consumer protection laws that address unfair and deceptive practices; it is a regulatory/compliance matter and does not itself constitute cyber insurance policy language or coverage terms.

Why it matters

The Consumer Privacy Protection Model Act (Model #674) matters primarily as a signal of how insurance regulators have grappled with consumer data privacy standards specific to the business of insurance, distinct from the broader wave of general state consumer data privacy statutes. For risk managers, brokers, and compliance professionals, the significance lies less in any binding effect (the draft was never adopted) and more in understanding the trajectory of insurance-sector privacy regulation and how licensees, including insurers, agents, and brokers, may eventually be governed in their collection, processing, retention, and sharing of consumers' personal information.

Who it's relevant to

Compliance and legal professionals at insurers, agencies, and brokerages
These professionals track NAIC model development because state adoption of any resulting model can impose obligations on how their organizations handle consumer personal information. The key takeaway is that #674 was set aside in 2024; compliance planning should focus on the revision of Model #672 and on the specific enactments of individual states rather than on #674 as a forthcoming standard.
Insurance brokers and agents
The #674 draft expressly contemplated applying data privacy requirements to licensees including agents and brokers, not just carriers. Even though the draft was abandoned, brokers and agents should understand that insurance-sector privacy obligations may reach their own data practices as the #672 revision proceeds, and should not assume privacy regulation is confined to insurers alone.
Risk managers evaluating regulatory and cyber exposure
Risk managers should distinguish regulatory privacy obligations from insurance coverage. A model law such as #674 (or the #672 revision) governs compliance duties; it does not define what a cyber policy covers. Whether regulatory defense costs or privacy-related liability are insured depends entirely on the specific policy wording, endorsements, and exclusions, subject to jurisdiction, and not on any NAIC model.
Underwriters assessing insureds' privacy governance
Underwriters may consider how insurance licensees manage consumer data as part of evaluating an account. Understanding that #674 was superseded, and that NAIC attention shifted to amending Model #672, helps underwriters frame questions about an insured's regulatory posture accurately rather than referencing an abandoned draft.

Inside Consumer Privacy Protection Model Act

Model #674 (Insurance Consumer Privacy Protection Model Law)
A draft insurance consumer privacy model law developed under the NAIC Privacy Protections (H) Working Group. It is important to note that this was a draft project, not an adopted model law. On June 12, 2024, the Working Group voted to set aside the #674 draft rather than advance it to adoption. As of August 2026 it is no longer an active NAIC project, so it does not represent enforceable model text that states are being asked to enact.
Decision to revise Model #672 instead
Rather than proceed with the new #674 draft, the NAIC directed effort toward revising the existing Privacy of Consumer Financial and Health Information Regulation (Model #672). Practitioners tracking insurance consumer privacy developments should therefore follow work on #672 rather than #674.
Subject matter scope (consumer privacy in insurance)
The abandoned draft addressed how insurers and their business partners collect, use, share, and protect consumer personal information. This is a regulatory and compliance topic concerning data-handling obligations; it is distinct from cyber insurance coverage terms and is not itself a coverage grant, exclusion, or resilience control.
Distinction from cyber coverage and resilience concepts
A privacy model law of this type sets conduct and data-protection standards for regulated entities. It is separate from first-party cyber coverage (such as data restoration or business interruption) and third-party cyber liability (such as privacy claims and regulatory defense), though the compliance obligations it would create could interact with how regulatory-defense coverage responds, subject to specific policy wording.

Common questions

Answers to the questions practitioners most commonly ask about Consumer Privacy Protection Model Act.

Is the Insurance Consumer Privacy Protection Model Law (#674) currently being developed by the NAIC?
No. This is a common misconception. The NAIC Privacy Protections (H) Working Group voted on June 12, 2024 to set aside the draft Model #674. Rather than advancing that model to adoption, the group opted to revise the existing Privacy of Consumer Financial and Health Information Regulation (#672). As a result, #674 is no longer an active drafting project. Any reference describing #674 as a current draft 'being developed' is outdated and should not be relied upon for compliance planning.
Should insurers and brokers prepare their privacy compliance programs around the adoption of Model #674?
No, and treating #674 as forthcoming law would misdirect compliance resources. Because the NAIC set the draft aside in 2024 in favor of revising Model #672, planning around #674's adoption assumes a premise that no longer holds. Organizations tracking NAIC privacy developments should instead follow the work on revising #672, while recognizing that any revision remains subject to change and, as a model, would not have legal effect unless and until adopted by individual states.
Where should compliance teams direct their attention now that #674 has been set aside?
Attention should shift to the NAIC's effort to revise the existing Privacy of Consumer Financial and Health Information Regulation (#672), which the Working Group chose to pursue instead. Because this remains an evolving effort, teams should monitor Working Group materials and meeting minutes for current status rather than relying on the abandoned #674 framing. As with any NAIC model, the practical requirements that ultimately apply depend on what each state adopts, and adoption can vary in timing, wording, and scope across jurisdictions.
Does the setting-aside of #674 change an insurer's existing privacy obligations?
The 2024 decision to set aside #674 does not by itself create or remove obligations, because #674 had not been adopted as law. Existing privacy obligations continue to derive from currently applicable sources, including state adoptions of prior NAIC models such as #672, other state insurance privacy requirements, and any broader privacy regimes that apply based on jurisdiction and the nature of the data handled. Insurers should map their obligations against the frameworks actually in force in each state where they operate rather than against a discontinued draft.
How does the distinction between a model law and enacted law affect implementation here?
An NAIC model, whether #674 or a revised #672, has no direct legal force. It becomes binding only when a state legislature or regulator adopts it, and states frequently modify model language during adoption. This means implementation questions cannot be answered from the model text alone; the operative requirements depend on the specific state adoption and its wording. Because #674 was set aside before adoption, it produced no such enacted requirements, and implementation planning should track the actual statutes and regulations in each relevant jurisdiction.
How should this development be reflected when assessing regulatory-defense and privacy liability exposure under a cyber policy?
Regulatory-defense and privacy-related coverage under a cyber policy is third-party coverage, and whether a given regulatory proceeding or privacy claim is covered depends on the specific policy wording, endorsements, exclusions, and conditions, as well as the jurisdiction. The status of a particular NAIC model does not itself determine coverage. In assessing exposure, focus on the privacy requirements actually enforceable in the relevant states, and evaluate how the policy's definitions of regulatory proceedings, wrongful acts, and covered claims respond to those enforceable obligations rather than to a discontinued draft model.

Common misconceptions

Model #674 is a current NAIC draft still being developed toward adoption.
This is outdated. On June 12, 2024 the NAIC Privacy Protections (H) Working Group voted to set aside the #674 draft and instead revise the existing Model #672. As of August 2026, #674 is no longer an active project and should not be described as advancing toward adoption.
An NAIC model law, once drafted or adopted, is automatically binding law in the states.
NAIC model laws are templates, not directly enforceable law. Each state legislature or insurance regulator must independently adopt or adapt a model for it to have legal force, and states frequently modify or decline model text. A draft that has been set aside creates no obligations at all.
An insurance consumer privacy model law is a cyber insurance policy provision or determines what a cyber policy covers.
A privacy model law sets data-handling and conduct standards for insurers; it is a regulatory instrument, not policy wording. Whether any resulting compliance failure or regulatory action is covered depends on the specific cyber or E&O policy terms, endorsements, exclusions, and jurisdiction.

Best practices

Treat #674 as a discontinued draft: do not build compliance planning or client advisories on the assumption that it will be adopted, and correct any internal materials that describe it as an active project.
Redirect monitoring toward the NAIC's revision of the Privacy of Consumer Financial and Health Information Regulation (Model #672), since that is where insurance consumer privacy work has been directed.
Verify the current status of any NAIC model directly against primary NAIC records before relying on it, because working-group priorities and drafts can be set aside or reassigned.
Keep regulatory privacy obligations analytically separate from cyber insurance coverage analysis, and assess whether regulatory-defense or privacy liability coverage would respond to a given exposure based on the actual policy wording rather than on model-law status.
Confirm how privacy obligations are actually imposed in each relevant jurisdiction through adopted state statutes and regulations, rather than through unadopted or abandoned model drafts.
Document the source and date of any model-law status statement in client-facing work so that outdated framing can be identified and updated as NAIC activity evolves.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide