US Privacy Law United States (Federal)

GLBA Privacy and Safeguards Rules: Compliance Guide

The Gramm-Leach-Bliley Act's Privacy Rule, the amended Safeguards Rule, the 2024 breach-reporting duty, who counts as a financial institution, and FTC enforcement.

Regulation

Gramm-Leach-Bliley Act (15 U.S.C. 6801-6809); Privacy Rule (Regulation P); FTC Safeguards Rule (16 CFR Part 314, amended 2021-2023)

Max Penalty

FTC civil penalties up to $53,088 per violation for rule breaches; banking regulators impose institution-level orders and fines

Enforcing Authority

FTC (non-bank institutions); CFPB and prudential banking regulators; state insurance commissioners

Official Source

www.ftc.gov

Executive Summary

  • GLBA governs nonpublic personal information (NPI) held by 'financial institutions,' a definition reaching far past banks: mortgage brokers, auto dealers with financing, tax preparers, collection agencies, payday lenders, higher-ed institutions handling federal loans, and fintechs.
  • The Privacy Rule requires initial and annual privacy notices and an opt-out before sharing NPI with nonaffiliated third parties (with exceptions for service providers and joint marketing).
  • The amended Safeguards Rule (fully effective June 2023) is prescriptive: a qualified individual, written risk assessments, encryption, MFA, access reviews, continuous monitoring or annual penetration testing, vendor oversight, and incident response plans.
  • Since May 2024, FTC-regulated institutions must report security events affecting 500+ consumers' unencrypted information to the FTC within 30 days, GLBA's first federal breach-reporting requirement.
  • Enforcement: the FTC's actions against ACRAnet, SkyMed, Drizly-adjacent cases, and its 2023 order against Blackbaud, plus exam-driven enforcement by banking agencies; GLBA compliance also gates state privacy law exemptions.

GLBA is two regimes wearing one acronym. The Privacy Rule is 1999-vintage notice-and-opt-out, mostly stable, mostly paperwork. The Safeguards Rule stopped being paperwork in 2023: it now reads like a security standard, named accountability, MFA, encryption, penetration testing, vendor oversight, enforced by an FTC that added a public 30-day breach-reporting duty in 2024. And because state privacy laws pivot their exemptions on GLBA status, getting the definitional analysis right determines which of two entire compliance worlds you live in.

LawGLBA; 16 CFR Part 314 (Safeguards), Regulation P (Privacy)
Covers’Financial institutions’ + their service providers
Safeguards deadlineFully effective June 9, 2023
Breach reporting500+ consumers, 30 days to FTC (from May 2024)
PenaltyUp to $53,088 per violation (FTC)

Making the two rules operational

Settle the coverage question in writing. The significantly-engaged analysis decides GLBA status, and downstream, your entity- versus data-level treatment under each state privacy law. Revisit it when business models change; adding financing or refund-advance products changes the answer.

Reconcile the privacy notice with reality. Diff the model form against actual third-party flows, ad pixels and data-append vendors included. A notice promising no sharing while a tracker inventory shows NPI-adjacent data leaving the site is an FTC deception case waiting.

Build the Safeguards program to the element list. Qualified individual with board reporting, risk assessment, the enumerated technical controls (MFA everywhere customer information lives, encryption, access reviews, logging), testing cadence, training, and incident response. New York licensees should build once to the stricter NYDFS Part 500 spec and inherit GLBA compliance.

Contract and oversee service providers. Selection diligence, safeguard requirements in contracts, and periodic reassessment, the same lifecycle as NYDFS 500.11, with the FTC’s Blackbaud action showing vendor incidents become customer notification events.

Wire the 30-day clock into incident response. FTC portal notice, state consumer notices, banking-regulator duties, and contractual customer notifications each run on different clocks from one incident; a single notification matrix prevents the miss.

Non-NPI data on your public site still answers to the state laws; check what your web properties collect and share with a free scan.

Frequently Asked Questions

Are we a 'financial institution' under GLBA?

If you are significantly engaged in financial activities as defined by the Bank Holding Company Act's implementing rules: lending, loan brokering or servicing, financial advisory, debt collection, check cashing, tax preparation, wiring money, and financing product sales all qualify. Car dealerships arranging financing, universities administering Perkins or Direct Loans, and buy-now-pay-later fintechs are covered. Merely accepting credit cards is not. The test is the activity, not the industry label.

What does the Privacy Rule require day to day?

A clear initial privacy notice at the customer relationship's start, annual notices thereafter (streamlined if practices haven't changed and no opt-out applies), accurate description of sharing practices, and a reasonable opt-out mechanism before NPI goes to nonaffiliated third parties outside the exceptions. The model form provides a safe harbor. The recurring failure mode is notices that no longer match actual data flows, particularly after adding analytics, ad-tech, or data-monetization arrangements.

What are the amended Safeguards Rule's hard requirements?

Nine program elements including: a designated qualified individual reporting periodically (at least annually) to the board; written risk assessments; specific controls, access management with reviews, encryption of customer information at rest and in transit (or documented CISO-approved alternatives), MFA for any system with customer information, secure development, logging, and change management; continuous monitoring or annual pen tests plus semiannual vulnerability scans; workforce training; service-provider oversight; and a written incident response plan. Institutions under 5,000 consumers get partial relief.

What is the 30-day FTC notification rule?

Effective May 13, 2024: FTC-regulated financial institutions must notify the FTC, via its online portal, within 30 days of discovering a 'notification event,' unauthorized acquisition of unencrypted customer information involving at least 500 consumers. The reports are public. This runs alongside (not instead of) all 50 states' consumer breach-notification laws and any obligations to banking regulators, so incident-response plans need a consolidated notification matrix.

How does GLBA interact with the state privacy laws?

Most comprehensive state laws exempt GLBA-regulated data (data-level) and many exempt GLBA institutions entirely (entity-level), but the map is uneven: California exempts only the data, Oregon only the data, while Virginia and Texas exempt the institution. Marketing data, website analytics, and non-customer prospect data typically fall outside GLBA's NPI definition and thus outside the exemption, landing back in CCPA-style regimes. NYDFS Part 500 adds a stricter state security overlay for New York licensees.

Regulatory Crosswalk

NYDFS 23 NYCRR 500State privacy law GLBA exemptionsPCI DSS

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.