Gramm-Leach-Bliley Act
The Gramm-Leach-Bliley Act (GLBA) is a United States federal law that requires financial institutions—companies offering products or services such as loans, financial advice, or investment products—to protect the privacy and security of consumers' personal financial information. It generally limits when such institutions may share a consumer's nonpublic personal information and requires them to safeguard it. Because it is a statute, GLBA carries legal force for the institutions within its scope, unlike a voluntary standard or framework.
Enacted by the 106th United States Congress in 1999 and also known as the Financial Services Modernization Act of 1999, GLBA imposes privacy and information security obligations on entities that qualify as 'financial institutions' under the statute and its implementing regulations. Its provisions generally restrict the circumstances under which a financial institution may disclose a consumer's 'nonpublic personal information' to nonaffiliated third parties, and require institutions to protect the privacy and security of that information. The definitional scope of 'financial institution' is broad and covers many entities that offer financial products or services, so applicability is fact-specific and should be assessed against the current statutory and regulatory text; enforcement and rulemaking are apportioned among functional regulators (including the FTC for entities within its jurisdiction). This entry addresses GLBA generally and does not detail the specific rule provisions, exemptions, notice requirements, or enforcement thresholds, which readers should verify against the latest authoritative sources, as statutes and implementing regulations are periodically amended.
Why it matters
GLBA is one of the foundational US federal laws governing how personal financial information is handled, and it applies to a broad range of entities that offer financial products or services—not only banks. Because it is a statute rather than a voluntary standard, institutions within its scope face legally enforceable obligations to protect the privacy and security of consumers' nonpublic personal information and to limit how that information is disclosed. For compliance officers and legal counsel, understanding whether an organization qualifies as a 'financial institution' under GLBA is a threshold question, since the statutory definition is broad and can reach entities that do not think of themselves as traditional financial firms.
The stakes are practical: mishandling consumer financial information can expose an organization to enforcement by its functional regulator, including the FTC for entities within its jurisdiction. GLBA sits alongside other US sectoral privacy and security laws, and it should not be conflated with general data protection regimes such as the GDPR, which operate under a different legal framework and jurisdictional scope. Determining which obligations apply, and to which data, depends on the specific facts of an organization's activities.
Because GLBA's applicability is fact-specific and its implementing regulations are periodically amended, professionals should treat this entry as a general orientation rather than a definitive compliance checklist. The precise notice requirements, exemptions, safeguarding expectations, and enforcement thresholds must be verified against the current statutory and regulatory text and, where relevant, against the guidance of the applicable functional regulator.
Who it's relevant to
Inside GLBA
Common questions
Answers to the questions practitioners most commonly ask about GLBA.
