What Is GLBA (Gramm-Leach-Bliley Act)?

Also called: Gramm-Leach-Bliley, Financial Services Modernization Act of 1999

Related problems: We lend, advise or prepare taxes and don't know whether we count as a financial institution; Our insurer or examiner asked about our written information security program; Need vendors that handle customer financial data to meet safeguard requirements; Not sure when a breach of customer financial data must be reported

The Gramm-Leach-Bliley Act (GLBA) is a US federal law from 1999 that, among other things, sets privacy and security obligations for financial institutions. Its privacy provisions require institutions to tell customers how they share nonpublic personal information and to let them opt out of some sharing. Its safeguards provisions require a program to protect that information, and it outlaws pretexting, meaning obtaining customer financial information under false pretenses. Different regulators apply it to different kinds of institutions. This entry is an overview for buyers, not legal advice.

At a glance

  • GLBA covers “financial institutions” broadly, including many non-bank lenders, tax preparers, advisers and finance companies.
  • The privacy rules require notices about information sharing and an opt-out for some sharing with non-affiliated third parties.
  • The safeguards rules require a written information security program based on risk assessment; the FTC’s version spells out specific controls.
  • Institutions must oversee service providers that handle customer information, including by contract.
  • Rules and enforcement depend on the regulator: banking agencies, the SEC, state insurance regulators, the CFPB or the FTC.

What problem it solves

Financial institutions hold some of the most sensitive data people have: account numbers, income, credit history, tax records. GLBA, passed as part of a law that let banks, insurers and securities firms combine, set baseline rules so that customers know how their information is shared and can expect it to be protected.

The security side has grown in importance. The FTC’s updated Safeguards Rule turned general expectations into specific requirements for the many non-bank businesses it covers, such as encryption, multi-factor authentication and penetration testing. For a mid-market lender, tax firm or dealer group, that means an information security program that would stand up to an examiner or an FTC inquiry.

How it works

Financial Privacy Rule. Institutions give customers privacy notices explaining what they collect and share, and offer an opt-out before sharing nonpublic personal information with certain non-affiliated third parties. Rulemaking for most institutions sits with the Consumer Financial Protection Bureau (Regulation P), with the FTC keeping a rule for certain auto dealers.

Safeguards. Each institution maintains an information security program appropriate to its size and the sensitivity of its data. For FTC-regulated institutions, the Safeguards Rule requires a qualified individual to run it, a written risk assessment, access controls, encryption, multi-factor authentication (MFA), monitoring or periodic penetration testing and vulnerability scanning, training, change management, secure disposal, an incident response plan and service provider oversight.

Breach notification. FTC-covered institutions must notify the FTC of qualifying data breaches involving at least 500 consumers. Other regulators have their own notice rules, and state laws add more.

Pretexting. The act prohibits obtaining customer information through false pretenses, which informs training and verification procedures for call centers and help desks.

Rules and regulators

GLBA has no certification levels. Its structure is a set of rules, applied by the regulator that oversees each type of institution.

Part or role Who it applies to What is required Typical evidence
Financial Privacy Rule Financial institutions sharing nonpublic personal information Privacy notices and opt-out for some third-party sharing Privacy notice, opt-out records
FTC Safeguards Rule Non-bank institutions under FTC jurisdiction Written program with specified elements; FTC breach notice Written program, risk assessment, board reports, test results
Banking and securities safeguards Banks, credit unions, broker-dealers and advisers, under their own regulators Security programs and incident rules set by those regulators Examination results, policies
Small-institution exemption FTC-covered institutions with customer information on fewer than 5,000 consumers Exempt from some Safeguards Rule provisions Documented customer count
Service provider Vendors handling customer information for an institution Safeguards required by contract; subject to oversight Contract terms, security reports

When it matters for buyers

  • When you lend, broker, advise or prepare taxes. You may be a financial institution even if you don’t think of yourself as one.
  • When choosing cloud, MSP, contact center or document-handling vendors. You must assess and oversee them, so you need evidence and contract terms.
  • When an examiner, insurer or partner asks about your program. The written program, risk assessment and test results are what they want to see.
  • When an incident involves customer financial data. Notification clocks may start running.

Our governance, risk and compliance overview covers program-building help, and our penetration testing and vulnerability management overviews cover required testing.

Questions to ask vendors

  • Will you contractually commit to safeguards appropriate for customer financial information?
  • What independent security reports can you share, and are they scoped to this service?
  • Do you encrypt our data in transit and at rest, and who controls the keys?
  • Is multi-factor authentication enforced for everyone who can reach our data, including your staff?
  • How quickly will you notify us of an incident, so we can meet regulator deadlines?
  • How do you verify callers and prevent pretexting in your support desk?

How it differs from PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) is a contractual standard from the card brands that applies to anyone storing, processing or transmitting cardholder data, whether or not they are a financial institution. GLBA is a federal law covering financial institutions and a much wider range of customer financial information. Many lenders and dealers need both. Public financial companies also face the Sarbanes-Oxley Act (SOX), which focuses on financial reporting controls. All of these feed a combined data security compliance program.

Frequently Asked Questions

Who counts as a financial institution under GLBA?
More businesses than the name suggests. Besides banks, it can include mortgage lenders and brokers, payday lenders, tax preparers, credit counselors, some investment advisers, finance companies and auto dealers that arrange financing. Whether you are covered depends on the activities you perform, so check with counsel; this is not legal advice.
What does the FTC Safeguards Rule require?
For financial institutions under FTC jurisdiction, a written information security program run by a designated qualified individual, based on a written risk assessment, with safeguards such as access controls, encryption, multi-factor authentication, monitoring and testing, staff training, service provider oversight, an incident response plan and regular reports to the board or a senior officer.
Do we have to report breaches under GLBA?
It depends on your regulator. Under the FTC Safeguards Rule, covered institutions must notify the FTC within 30 days of discovering unauthorized acquisition of unencrypted customer information involving at least 500 consumers. Banks and securities firms follow their own regulators' rules, and state breach laws can also apply.
Does GLBA apply to our IT and cloud vendors?
Indirectly. GLBA places duties on financial institutions, which must select service providers that can safeguard customer information, require safeguards by contract and oversee them. In practice your vendors will be asked for security evidence and contract terms that support your program.
Are small financial institutions exempt?
Partly. Under the FTC Safeguards Rule, institutions that hold customer information on fewer than 5,000 consumers are exempt from some provisions, such as the written risk assessment and board reporting, but not from the rule as a whole.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.