Gramm-Leach-Bliley Act (GLBA) Compliance Guide 2026

11 min read

Two people working on a laptop with "PRIVACY LAW" text overlay.

The Gramm-Leach-Bliley Act now has a 30-day deadline. Are you ready?

Most financial institutions can point to a written incident response plan and call their Gramm-Leach-Bliley Act compliance done. Since May 2024, that plan has to do more than exist on paper: if a breach hits 500 or more consumers' unencrypted data, the institution has 30 days to detect it, understand its scope, and report it to the FTC. A plan nobody has tested against that clock is a plan that's likely to miss it.

Gramm-Leach-Bliley Act is a federal law that sets requirements for safeguarding consumer financial information, enacted in 1999 as part of the broader Financial Modernization Act. It applies to banks, credit unions, insurance companies, investment firms, and a wider list of non-bank businesses than most people expect. What actually counts as compliance under it has changed more in the last three years than in the two decades before that.

What the Gramm-Leach-Bliley Act actually requires

GLBA compliance rests on three rules. The Financial Privacy Rule requires clear disclosure of data-sharing practices and gives consumers the right to opt out of having their information shared with certain third parties. The Safeguards Rule requires a comprehensive security program to protect customer information. The Pretexting Rule prohibits obtaining someone's financial information through deceptive means, and requires institutions to have procedures that guard against it.

The Safeguards Rule is where most of the actual compliance work lives, and it's also the part of GLBA that's changed the most.

The Safeguards Rule got a lot more specific, then added a deadline

For years, the Safeguards Rule asked for “reasonable” security without much specificity. The FTC's 2021 overhaul replaced that with ten concrete elements: a designated qualified individual to run the security program, a written risk assessment, access controls, encryption of customer data at rest and in transit, multi-factor authentication, continuous monitoring, staff training, oversight of service providers, a written incident response plan, and regular reporting to the board or a senior officer.

Then, in October 2023, the FTC added something the original Safeguards Rule never had: a breach notification requirement. Financial institutions under FTC jurisdiction now have to report a “notification event,” unauthorized acquisition of unencrypted customer information affecting 500 or more consumers, to the FTC within 30 days of discovery. The amendment took effect in May 2024, and there's no carve-out for breaches that seem unlikely to cause harm. If unencrypted data belonging to 500-plus people was acquired without authorization, the clock starts.

That 30-day window is the practical test of whether an incident response plan is real. Detecting a breach, scoping which systems and how many consumers were affected, and preparing a report all have to happen inside a window that used to have no formal deadline at all.

Who has to comply

GLBA applies to the obvious financial institutions, banks, credit unions, insurance companies, securities firms, mortgage lenders, and loan brokers, but its reach extends further. Tax preparers, debt collectors, and real estate settlement services can all fall under it depending on what they do with customer financial data. A useful test: if a business collects personal financial information, helps customers get loans or credit, processes financial transactions beyond simple payments, or receives customer data from a financial institution, GLBA likely applies.

Penalties scale with how seriously that gets ignored. Financial institutions can face civil and criminal penalties of up to $100,000 per violation, officers and directors up to $10,000 individually, and individuals can face up to five years in prison for the most serious violations.

See how Privacy, Legal & Risk teams at financial institutions build audit-ready compliance or explore Transcend for fintech.

Fintech

Vendor risk doesn't stay outside the institution's walls

GLBA compliance doesn't stop at an institution's own systems. Any vendor with access to customer financial data has to be vetted for security practices before the relationship starts, and monitored afterward, since a vendor's breach can trigger the same 30-day notification obligation as an internal one. Due diligence, a documented vendor security review, and ongoing audits are the baseline expectation, not a one-time checkbox at onboarding.

Incident response has to be tested, not just written

An incident response plan needs to name who does what during a breach: who detects it, who scopes it, who decides when the 500-consumer threshold has been crossed, and who prepares the FTC filing. Regular tabletop exercises are how an institution finds out whether that plan works before a real breach forces the question. Most breaches don't come from sophisticated attacks. They come from outdated software, weak passwords, and access controls nobody reviewed in a while, which is exactly what data minimization, encryption of sensitive personal information, and routine security audits are built to catch before they become a 30-day countdown.

Enforcement spans more than one agency

GLBA enforcement is split across regulators depending on the type of institution: the FTC covers non-bank financial institutions, the Office of the Comptroller of the Currency covers national banks, the FDIC covers state-chartered banks outside the Federal Reserve System, and the National Credit Union Administration covers credit unions. Each enforces the same underlying Safeguards Rule expectations, which means an institution's regulator changes who reviews its compliance, not what it has to do.

Get a demo to see how Transcend helps financial institutions meet GLBA's Safeguards Rule and 30-day breach notification requirements year-round.

Contact us

A smiling woman with long, blond hair stands outdoors against a blurred background of greenery, wearing a maroon top.

By Morgan Sullivan

Senior Marketing Manager II, Strategic Accounts

January 17, 2026

Share this article