US Federal Law United States

GLBA Privacy Notices: The Privacy Rule and Opt-Out Rights

GLBA Privacy Rule requirements: initial and annual notices, the model form safe harbor, opt-out rights for nonaffiliated sharing, and how state laws layer on top.

Regulation

GLBA Privacy Rule (Regulation P, 12 CFR Part 1016, administered by the CFPB; FTC rule 16 CFR Part 313 for entities outside CFPB scope); FCRA affiliate-marketing opt-outs interact

Max Penalty

CFPB and FTC enforcement with civil penalties; notice failures also underpin UDAP claims and state-law violations

Enforcing Authority

CFPB (Regulation P for most institutions); FTC; prudential regulators; state attorneys general

Official Source

www.ftc.gov

Executive Summary

  • The GLBA Privacy Rule requires financial institutions to deliver clear notices of their information-sharing practices: an initial notice at the customer relationship's start and, with important exceptions, annual notices thereafter.
  • Consumers get a right to opt out before nonpublic personal information is shared with nonaffiliated third parties, subject to broad exceptions for service providers, joint marketing, and processing.
  • The federal model form provides a safe harbor: use it properly and the notice-content requirement is satisfied.
  • The FAST Act exception eliminates annual notices for institutions that share only within the exceptions and haven't changed their practices, most institutions qualify.
  • GLBA preempts only inconsistent, weaker state law: states may and do impose stronger financial-privacy protections, with California's CCPA/CalFIPA interplay the leading example.

GLBA’s Privacy Rule is the oldest running notice regime in American privacy law, and its quarter century of practice teaches an unglamorous lesson: the notice is easy, the accuracy is hard. The model form gives every institution safe-harbor language; the FAST Act spared most from annual mailings; the exceptions cover nearly all operational sharing. What remains is the part no template solves, whether the yes/no boxes match reality, in an era when ‘sharing’ includes the pixel on the account login page and the SDK in the mobile app. Institutions get sued over the gap between the form and the flows, not the form. Check the flows.

RuleRegulation P (12 CFR 1016); FTC 16 CFR 313
NoticesInitial at relationship start; annual unless FAST Act exception
Safe harborFederal model form, used faithfully
Opt-outNonaffiliated sharing outside exceptions; 30-day benchmark
Flat banAccount numbers to nonaffiliates for marketing
State layerStronger laws preserved (CalFIPA, CCPA data-level interplay)

Getting notices right

Reconcile the form against the flows. Every ‘No’ in the sharing table is a testable claim; web and app analytics on covered pages are the usual contradiction, and the FTC’s deception doctrine prices false notices.

Confirm your FAST Act eligibility annually. Exception-only sharing and unchanged practices; a new marketing partnership can silently revive the annual notice duty.

Integrate the FCRA opt-outs. Affiliate eligibility-information and marketing choices belong on the same form; FCRA obligations run on their own track.

Pair notices with the security side. The Safeguards Rule governs protection of the same NPI; the program build-out and vendor terms complete GLBA compliance.

The pixel on your login page is a sharing decision: see what your financial pages transmit with a free scan.

Frequently Asked Questions

Who gets which notice, and when?

The rule distinguishes consumers (individuals obtaining a financial product for personal purposes) from customers (consumers with an ongoing relationship). Customers: an initial privacy notice no later than when the relationship is established, and annual notices thereafter unless the FAST Act exception applies. Consumers who never become customers (a declined applicant, a one-time transaction user): a notice only before you share their nonpublic personal information with nonaffiliated third parties outside the exceptions, if you never so share, no notice is owed. Revised notices are required before practices change in ways the prior notice did not cover, with fresh opt-out opportunity. Delivery must be such that recipients can reasonably be expected to receive actual notice: in-hand, mail, or, for customers who agree, electronically; posting alone works only for the annual notice under specific conditions (statutory streamlining allows website posting where sharing is within exceptions).

What is nonpublic personal information, exactly?

Personally identifiable financial information plus any list, description, or grouping derived from it: information a consumer provides to obtain a financial product (application data), information resulting from transactions (account numbers, balances, payment history), and information otherwise obtained in providing the product (credit report contents, cookies collected on a banking site per the rule's examples). The 'publicly available' carve-out requires a reasonable basis to believe the information is lawfully public (recorded liens, listed phone numbers), a customer's mere name-plus-institution association is generally NPI because it reveals a financial relationship. Two consequences institutions miss: web and app data collected in delivering financial services is NPI, so ad-tech beacons on account pages are 'sharing' requiring analysis; and account numbers get special treatment, sharing them with nonaffiliates for marketing is flatly prohibited (12 CFR 1016.12), no opt-out available.

How does the opt-out actually work, and what escapes it?

Before sharing NPI with nonaffiliated third parties, the institution must give the notice, a clear opt-out right, a reasonable means to exercise it (toll-free number, form, online mechanism, requiring a letter is not reasonable), and reasonable time (30 days is the benchmark). Opt-outs last until revoked. The exceptions swallow much of the rule: service providers and joint marketing agreements (1016.13, with contractual confidentiality limits); processing and servicing transactions the consumer requested (1016.14); and the everything-else list (1016.15: fraud prevention, legal compliance, consumer-consented disclosures, regulators). Sharing within these exceptions requires no opt-out, which is why most institutions can honestly state 'we do not share except as permitted by law.' What the opt-out does catch: selling customer lists, data-broker feeds, and marketing arrangements outside joint-marketing contracts. Affiliate sharing is governed separately, FCRA Section 603(d) opt-outs for eligibility information and Section 624 for affiliate marketing use, and the model form integrates those choices.

What does the model form safe harbor require?

The two-page standardized form (adopted 2009 by the agencies jointly) provides a legal safe harbor for content: the tabular 'What? Why? How?' layout, the sharing-reasons table with yes/no answers and opt-out indicators, the definitions panel, and the contact mechanics. The safe harbor demands fidelity: use the prescribed structure, complete the table accurately for each sharing category (everyday business, marketing, joint marketing, affiliates' everyday business, affiliates' marketing, nonaffiliates' marketing), and keep the form's plain-language conventions. An institution may draft its own notice instead, clear and conspicuous, accurate, and complete, but then carries the burden the form would have absorbed. The recurring failure is not form choice but accuracy: a model form answering 'No' to nonaffiliate marketing sharing while the ad-tech stack transmits account-page data to platforms is not a formatting problem, it is a false notice, and UDAP exposure attaches to the lie.

How do state laws and the CCPA interact with GLBA notices?

GLBA sets a floor: Section 507 preempts only state provisions inconsistent with it, and stronger protections are expressly preserved. California illustrates the layering: CalFIPA (SB 1) imposes stricter opt-in/opt-out rules for some sharing, and the CCPA exempts data 'collected pursuant to' GLBA, an information-level, not entity-level, exemption. A bank's customer transaction data may be CCPA-exempt while the same bank's website marketing analytics, job-applicant data, and non-financial product lines are fully CCPA-covered, so 'we're GLBA-exempt' is never the whole answer for a financial institution in California, and CPRA's amendments narrowed comfort further. Other states replicate the pattern in their comprehensive laws (most exempt GLBA data or GLBA entities, but variably, entity-level exemptions in some, data-level in others). The compliance map therefore has three layers per institution: Regulation P federally, state financial-privacy statutes, and the state comprehensive laws' treatment of your non-GLBA data.

Regulatory Crosswalk

FCRA Sections 603(d)/624CCPA financial-data interplayState insurance privacy rules

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.