GLBA is two regimes wearing one acronym. The Privacy Rule is 1999-vintage notice-and-opt-out, mostly stable, mostly paperwork. The Safeguards Rule stopped being paperwork in 2023: it now reads like a security standard, named accountability, MFA, encryption, penetration testing, vendor oversight, enforced by an FTC that added a public 30-day breach-reporting duty in 2024. And because state privacy laws pivot their exemptions on GLBA status, getting the definitional analysis right determines which of two entire compliance worlds you live in.
| Law | GLBA; 16 CFR Part 314 (Safeguards), Regulation P (Privacy) |
|---|---|
| Covers | ’Financial institutions’ + their service providers |
| Safeguards deadline | Fully effective June 9, 2023 |
| Breach reporting | 500+ consumers, 30 days to FTC (from May 2024) |
| Penalty | Up to $53,088 per violation (FTC) |
Making the two rules operational
Settle the coverage question in writing. The significantly-engaged analysis decides GLBA status, and downstream, your entity- versus data-level treatment under each state privacy law. Revisit it when business models change; adding financing or refund-advance products changes the answer.
Reconcile the privacy notice with reality. Diff the model form against actual third-party flows, ad pixels and data-append vendors included. A notice promising no sharing while a tracker inventory shows NPI-adjacent data leaving the site is an FTC deception case waiting.
Build the Safeguards program to the element list. Qualified individual with board reporting, risk assessment, the enumerated technical controls (MFA everywhere customer information lives, encryption, access reviews, logging), testing cadence, training, and incident response. New York licensees should build once to the stricter NYDFS Part 500 spec and inherit GLBA compliance.
Contract and oversee service providers. Selection diligence, safeguard requirements in contracts, and periodic reassessment, the same lifecycle as NYDFS 500.11, with the FTC’s Blackbaud action showing vendor incidents become customer notification events.
Wire the 30-day clock into incident response. FTC portal notice, state consumer notices, banking-regulator duties, and contractual customer notifications each run on different clocks from one incident; a single notification matrix prevents the miss.
Non-NPI data on your public site still answers to the state laws; check what your web properties collect and share with a free scan.