Gramm-Leach-Bliley Act

Enacted in 1999, GLBA applies to companies that offer financial products or services, including banks, lenders, insurers, tax preparers, mortgage brokers, and increasingly fintech companies. Its two primary privacy provisions are the Financial Privacy Rule and the Safeguards Rule.

The Financial Privacy Rule requires covered institutions to provide customers with a privacy notice at account opening and annually thereafter. The Safeguards Rule requires a comprehensive information security program; the FTC updated it in 2023 to require specific controls including encryption, multi-factor authentication, and incident response planning.

GLBA compliance intersects with broader data governance requirements: organizations subject to GLBA typically also operate under CCPA, state insurance laws, and consumer protection frameworks, creating multi-regime compliance obligations that benefit from centralized data inventory and policy management.