The Gramm-Leach-Bliley Act (GLBA) is a US federal law from 1999 that, among other things, sets privacy and security obligations for financial institutions. Its privacy provisions require institutions to tell customers how they share nonpublic personal information and to let them opt out of some sharing. Its safeguards provisions require a program to protect that information, and it outlaws pretexting, meaning obtaining customer financial information under false pretenses. Different regulators apply it to different kinds of institutions. This entry is an overview for buyers, not legal advice.
At a glance
- GLBA covers “financial institutions” broadly, including many non-bank lenders, tax preparers, advisers and finance companies.
- The privacy rules require notices about information sharing and an opt-out for some sharing with non-affiliated third parties.
- The safeguards rules require a written information security program based on risk assessment; the FTC’s version spells out specific controls.
- Institutions must oversee service providers that handle customer information, including by contract.
- Rules and enforcement depend on the regulator: banking agencies, the SEC, state insurance regulators, the CFPB or the FTC.
What problem it solves
Financial institutions hold some of the most sensitive data people have: account numbers, income, credit history, tax records. GLBA, passed as part of a law that let banks, insurers and securities firms combine, set baseline rules so that customers know how their information is shared and can expect it to be protected.
The security side has grown in importance. The FTC’s updated Safeguards Rule turned general expectations into specific requirements for the many non-bank businesses it covers, such as encryption, multi-factor authentication and penetration testing. For a mid-market lender, tax firm or dealer group, that means an information security program that would stand up to an examiner or an FTC inquiry.
How it works
Financial Privacy Rule. Institutions give customers privacy notices explaining what they collect and share, and offer an opt-out before sharing nonpublic personal information with certain non-affiliated third parties. Rulemaking for most institutions sits with the Consumer Financial Protection Bureau (Regulation P), with the FTC keeping a rule for certain auto dealers.
Safeguards. Each institution maintains an information security program appropriate to its size and the sensitivity of its data. For FTC-regulated institutions, the Safeguards Rule requires a qualified individual to run it, a written risk assessment, access controls, encryption, multi-factor authentication (MFA), monitoring or periodic penetration testing and vulnerability scanning, training, change management, secure disposal, an incident response plan and service provider oversight.
Breach notification. FTC-covered institutions must notify the FTC of qualifying data breaches involving at least 500 consumers. Other regulators have their own notice rules, and state laws add more.
Pretexting. The act prohibits obtaining customer information through false pretenses, which informs training and verification procedures for call centers and help desks.
Rules and regulators
GLBA has no certification levels. Its structure is a set of rules, applied by the regulator that oversees each type of institution.
| Part or role | Who it applies to | What is required | Typical evidence |
|---|---|---|---|
| Financial Privacy Rule | Financial institutions sharing nonpublic personal information | Privacy notices and opt-out for some third-party sharing | Privacy notice, opt-out records |
| FTC Safeguards Rule | Non-bank institutions under FTC jurisdiction | Written program with specified elements; FTC breach notice | Written program, risk assessment, board reports, test results |
| Banking and securities safeguards | Banks, credit unions, broker-dealers and advisers, under their own regulators | Security programs and incident rules set by those regulators | Examination results, policies |
| Small-institution exemption | FTC-covered institutions with customer information on fewer than 5,000 consumers | Exempt from some Safeguards Rule provisions | Documented customer count |
| Service provider | Vendors handling customer information for an institution | Safeguards required by contract; subject to oversight | Contract terms, security reports |
When it matters for buyers
- When you lend, broker, advise or prepare taxes. You may be a financial institution even if you don’t think of yourself as one.
- When choosing cloud, MSP, contact center or document-handling vendors. You must assess and oversee them, so you need evidence and contract terms.
- When an examiner, insurer or partner asks about your program. The written program, risk assessment and test results are what they want to see.
- When an incident involves customer financial data. Notification clocks may start running.
Our governance, risk and compliance overview covers program-building help, and our penetration testing and vulnerability management overviews cover required testing.
Questions to ask vendors
- Will you contractually commit to safeguards appropriate for customer financial information?
- What independent security reports can you share, and are they scoped to this service?
- Do you encrypt our data in transit and at rest, and who controls the keys?
- Is multi-factor authentication enforced for everyone who can reach our data, including your staff?
- How quickly will you notify us of an incident, so we can meet regulator deadlines?
- How do you verify callers and prevent pretexting in your support desk?
How it differs from PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a contractual standard from the card brands that applies to anyone storing, processing or transmitting cardholder data, whether or not they are a financial institution. GLBA is a federal law covering financial institutions and a much wider range of customer financial information. Many lenders and dealers need both. Public financial companies also face the Sarbanes-Oxley Act (SOX), which focuses on financial reporting controls. All of these feed a combined data security compliance program.
