GLBA
By U.S. Congress
S. federal law that requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive customer financial data.
Definition
The Gramm-Leach-Bliley Act, or GLBA, is a U.S. federal law that requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive customer financial data. It applies broadly to banks, credit unions, insurance companies, and other businesses significantly engaged in financial activities, and its Safeguards Rule specifically requires those institutions to maintain a written information security program covering how customer data is protected.
Overview
GLBA was enacted primarily to modernize financial services regulation by removing barriers that had separated banking, securities, and insurance businesses, but it included privacy and security provisions specifically because the resulting consolidation meant financial institutions could combine and share far more customer financial data across business lines than before. Lawmakers recognized that customers needed both notice of how their data moved between affiliated and non-affiliated companies and assurance that the data itself was being protected. Mechanically, GLBA compliance rests on several components enforced primarily by the Federal Trade Commission and federal banking regulators. The Financial Privacy Rule requires institutions to provide customers with a privacy notice describing what information is collected and shared, and with whom, along with an opportunity to opt out of certain sharing with unaffiliated third parties. The Safeguards Rule, updated substantially in recent years, requires a written information security program with designated responsibility, risk assessment, access controls, encryption of customer data, and incident response planning, scaled to the institution's size and complexity. A separate Pretexting provision prohibits obtaining customer information under false pretenses. GLBA differs from sector-neutral privacy laws like CCPA in that it is sector-specific, applying to financial institutions broadly defined, including businesses like tax preparers, mortgage brokers, and check-cashing services that might not think of themselves as traditional financial companies. It also differs from HIPAA, which governs health information rather than financial data, though both share a similar structure of a privacy notice requirement paired with a technical safeguards mandate. In practice, financial institutions build compliance programs around annual or updated privacy notices, opt-out mechanisms for information sharing, and a documented information security program addressing the Safeguards Rule's specific elements, such as encryption of customer data in transit and at rest, multi-factor authentication for access to customer information systems, and regular security testing. Non-bank entities that fall under GLBA's broad financial institution definition, like auto dealers extending financing or tax preparation services, often need dedicated compliance effort since they may not have traditional banking compliance infrastructure already in place. A key limitation is that GLBA's scope is defined by activity, being significantly engaged in financial activities, rather than by industry label, so entities can be surprised to discover they qualify. Its Safeguards Rule updates brought more specific technical requirements that smaller institutions without dedicated security staff can find burdensome to implement fully, often requiring outside expertise. Where an institution also handles health data or California consumer data, GLBA compliance must be layered alongside HIPAA or CCPA obligations rather than substituting for them.
Key Concepts
- Requires privacy notices describing financial data collection and sharing
- Gives customers an opt-out right for certain third-party data sharing
- Mandates a written information security program under the Safeguards Rule
- Applies broadly to financial institutions beyond traditional banks
- Requires encryption and access controls for customer information systems
- Prohibits obtaining customer information through pretexting
- Enforced by the Federal Trade Commission and federal banking regulators
- Scales security program requirements to institution size and complexity