Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Category: Regulations & Laws

Gramm-Leach-Bliley Act

Also known as: GLBA, GLB Act, Financial Services Modernization Act of 1999
Simply put

The Gramm-Leach-Bliley Act (GLBA) is a United States federal law that requires financial institutions—companies offering products or services such as loans, financial advice, or investment products—to protect the privacy and security of consumers' personal financial information. It generally limits when such institutions may share a consumer's nonpublic personal information and requires them to safeguard it. Because it is a statute, GLBA carries legal force for the institutions within its scope, unlike a voluntary standard or framework.

Formal definition

Enacted by the 106th United States Congress in 1999 and also known as the Financial Services Modernization Act of 1999, GLBA imposes privacy and information security obligations on entities that qualify as 'financial institutions' under the statute and its implementing regulations. Its provisions generally restrict the circumstances under which a financial institution may disclose a consumer's 'nonpublic personal information' to nonaffiliated third parties, and require institutions to protect the privacy and security of that information. The definitional scope of 'financial institution' is broad and covers many entities that offer financial products or services, so applicability is fact-specific and should be assessed against the current statutory and regulatory text; enforcement and rulemaking are apportioned among functional regulators (including the FTC for entities within its jurisdiction). This entry addresses GLBA generally and does not detail the specific rule provisions, exemptions, notice requirements, or enforcement thresholds, which readers should verify against the latest authoritative sources, as statutes and implementing regulations are periodically amended.

Why it matters

GLBA is one of the foundational US federal laws governing how personal financial information is handled, and it applies to a broad range of entities that offer financial products or services—not only banks. Because it is a statute rather than a voluntary standard, institutions within its scope face legally enforceable obligations to protect the privacy and security of consumers' nonpublic personal information and to limit how that information is disclosed. For compliance officers and legal counsel, understanding whether an organization qualifies as a 'financial institution' under GLBA is a threshold question, since the statutory definition is broad and can reach entities that do not think of themselves as traditional financial firms.

The stakes are practical: mishandling consumer financial information can expose an organization to enforcement by its functional regulator, including the FTC for entities within its jurisdiction. GLBA sits alongside other US sectoral privacy and security laws, and it should not be conflated with general data protection regimes such as the GDPR, which operate under a different legal framework and jurisdictional scope. Determining which obligations apply, and to which data, depends on the specific facts of an organization's activities.

Because GLBA's applicability is fact-specific and its implementing regulations are periodically amended, professionals should treat this entry as a general orientation rather than a definitive compliance checklist. The precise notice requirements, exemptions, safeguarding expectations, and enforcement thresholds must be verified against the current statutory and regulatory text and, where relevant, against the guidance of the applicable functional regulator.

Who it's relevant to

Compliance officers at financial institutions
Those responsible for regulatory compliance at banks, lenders, financial advisers, investment firms, and other entities offering financial products or services should assess whether their organization falls within GLBA's broad definition of 'financial institution' and, if so, map its privacy and information security obligations against the current statutory and regulatory text.
Legal counsel and privacy specialists
Counsel advising organizations that handle consumers' nonpublic personal information need to understand GLBA's restrictions on disclosure to nonaffiliated third parties, how it differs from voluntary standards and from other privacy regimes, and which functional regulator has jurisdiction over a given entity. Application to specific circumstances requires professional judgment.
Information security professionals
Security teams supporting in-scope financial institutions are relevant to GLBA because the law includes information security provisions requiring the protection of consumers' personal financial information, alongside its privacy requirements. Note that GLBA's privacy and security obligations are distinct and should not be treated as interchangeable.
Auditors and assessors
Professionals evaluating an organization's handling of financial information should recognize that GLBA is a binding statute rather than a certification scheme, and that assessing conformance depends on the entity's specific activities, applicable functional regulator, and the current version of the implementing regulations.

Inside GLBA

Financial Privacy Rule
Governs the collection and disclosure of customers' nonpublic personal information by financial institutions. It generally requires institutions to provide privacy notices describing their information-sharing practices and, in many cases, to offer consumers a right to opt out of certain disclosures to nonaffiliated third parties. The precise scope and exceptions should be verified against the current statutory text and implementing regulations.
Safeguards Rule
Requires covered financial institutions to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards appropriate to the institution's size, complexity, and the sensitivity of the information handled. This addresses security rather than privacy, and its specific requirements have been updated over time, so practitioners should confirm the applicable version.
Pretexting Provisions
Address the practice of obtaining customer information under false pretenses (pretexting), generally prohibiting the fraudulent acquisition of nonpublic personal financial information. These provisions target social-engineering and impersonation tactics used to extract account information.
Covered 'Financial Institution' Scope
GLBA applies to entities that are 'significantly engaged' in financial activities, a category that extends beyond traditional banks to include, in many cases, lenders, certain brokers, and other financial service providers. Whether a given entity is covered is fact-specific and should be assessed against the definition in the applicable rules.
Regulatory and Enforcement Framework
GLBA is a United States federal law, and enforcement is generally divided among functional regulators depending on the type of institution, with the Federal Trade Commission and various financial regulators playing roles. Enforcement responsibility and interpretation vary by sector, so the relevant regulator for a specific institution should be identified.

Common questions

Answers to the questions practitioners most commonly ask about GLBA.

Does the GLBA apply to any organization that handles consumers' personal financial information?
No. The GLBA applies to "financial institutions" as defined for its purposes, meaning entities significantly engaged in offering financial products or services in the United States. The definition reaches beyond traditional banks to include entities such as lenders, certain insurers, securities firms, and some financial advisers, but it is not a general commercial privacy law covering every business that holds financial data. Whether a particular entity is a covered financial institution is a fact-specific determination that should be verified against the current statutory text and the applicable regulator's implementing rules.
Is the GLBA essentially the U.S. equivalent of the GDPR?
No. The two should not be conflated. The GLBA is a sector-specific U.S. federal law directed at financial institutions and centered on the privacy and safeguarding of certain nonpublic personal information, whereas the GDPR is a comprehensive EU data protection regulation applying broadly across sectors and resting on distinct principles, roles, and rights. They differ in scope, jurisdiction, governing concepts, and enforcement structure. Meeting one does not establish compliance with the other, and organizations subject to both must address each on its own terms.
How do the GLBA's privacy and safeguards obligations relate to one another in practice?
The GLBA is generally implemented through distinct but complementary components: privacy-related requirements addressing how covered institutions handle and disclose nonpublic personal information (including notices and, in many cases, opt-out mechanisms for certain sharing), and safeguards-related requirements addressing the security of that information. Privacy and security are related but distinct disciplines here, and both typically need to be addressed. Because the specific obligations, notice content, and safeguards expectations are set out in implementing rules and may be interpreted differently across regulators, readers should verify the current requirements applicable to their institution.
Which regulator enforces the GLBA against a given institution?
Enforcement responsibility under the GLBA is generally allocated among multiple U.S. federal and state authorities depending on the type of institution, rather than resting with a single agency. The specific enforcing authority for a particular entity turns on its charter, sector, and the functional regulator with jurisdiction over it. Because these allocations and the associated implementing rules can change, institutions should confirm which authority oversees them and follow that regulator's current requirements and guidance.
What should an organization do first to assess whether the GLBA applies to it?
A practical starting point is to determine, based on the statutory definition and applicable implementing rules, whether the organization qualifies as a covered financial institution and whether the information it handles falls within the categories the GLBA protects. This is a threshold, fact-specific analysis that depends on the nature of the products or services offered and the data involved. Where the answer is uncertain, organizations commonly document the analysis and confirm the conclusion against the current official text and relevant regulator guidance, applying professional judgment to their particular circumstances.
Does complying with the GLBA relieve an organization of other privacy or security obligations?
Generally no. GLBA compliance addresses the obligations arising under that law for covered institutions and the categories of information it protects; it does not, by itself, satisfy obligations that may arise under other U.S. federal laws, state laws, sector-specific rules, contractual commitments, or non-U.S. regimes. Organizations frequently remain subject to multiple, overlapping requirements simultaneously. Determining how these interact for a specific organization requires assessment against each applicable authority and professional judgment; this entry is informational and does not constitute legal advice.

Common misconceptions

GLBA is a voluntary standard or best-practice framework that institutions can choose to adopt.
GLBA is a binding United States federal statute carrying legal force for covered financial institutions, not a voluntary standard like ISO/IEC 27001 or SOC 2. Compliance is a legal obligation for entities within its scope, though the specific requirements depend on the institution's activities and applicable implementing rules.
GLBA is only about data security and protecting information from breaches.
GLBA addresses both privacy and security through distinct components. The Financial Privacy Rule governs how customer information is collected and shared, while the Safeguards Rule governs how it is protected. Treating GLBA solely as a security mandate overlooks its privacy notice and opt-out obligations, which are separate concerns.
GLBA applies to any organization that handles personal or financial data.
GLBA's scope is generally limited to entities that qualify as 'financial institutions' significantly engaged in financial activities, within the United States. Organizations outside that definition are not directly subject to GLBA, though they may face other regulations. Coverage is fact-specific and should be confirmed against the applicable definitions.

Best practices

Determine whether your organization meets the definition of a covered 'financial institution' under GLBA before assuming applicability, and document that determination against the current rule text rather than relying on general categories.
Maintain separate but coordinated programs for the Financial Privacy Rule and the Safeguards Rule, recognizing that privacy notice/opt-out obligations and information security obligations are distinct requirements addressed by different components.
Develop and keep current a written information security program scaled to your institution's size, complexity, and the sensitivity of the data handled, and review it against the latest version of the Safeguards Rule, which has been updated over time.
Identify the functional regulator responsible for your institution type, since GLBA enforcement is divided among multiple regulators and interpretation and enforcement practice can differ by sector.
Implement controls and staff training to address pretexting and social-engineering risks, given GLBA's provisions targeting the fraudulent acquisition of customer information.
Verify all specific requirements, effective dates, and rule versions against current official sources, and engage qualified legal or compliance professionals to apply GLBA to your particular circumstances rather than relying on general definitions.
Promotional banner for the Penetration Report Template Kit