Nonpublic Personal Information
Nonpublic Personal Information (NPI) is personal financial information that a financial institution collects about a consumer and that is not publicly available. It generally includes information a consumer provides when obtaining a financial product or service, and it must be protected from unauthorized disclosure. NPI is a concept specific to U.S. financial privacy law rather than a universal privacy term.
Under the U.S. Gramm-Leach-Bliley Act (GLBA) and its implementing Privacy Rule, Nonpublic Personal Information (NPI) generally means personally identifiable financial information that is not publicly available, obtained by a financial institution in connection with offering or delivering a financial product or service to an individual for personal, family, or household purposes. NPI centers on 'personally identifiable financial information'—for example, information a consumer supplies on an application or that arises from a transaction—and is distinct from information lawfully made available to the public. The term is defined by regulation and applies to entities that qualify as financial institutions under GLBA within the United States; it should not be conflated with broader privacy-law concepts such as 'personal data' under the EU GDPR, which has different scope and definitions. Application to specific data elements and entities is fact-specific, and readers should verify the precise definition and any exclusions against the current text of the GLBA Privacy Rule and related guidance, as regulatory provisions may be amended.
Why it matters
Nonpublic Personal Information sits at the center of U.S. financial privacy obligations under the Gramm-Leach-Bliley Act (GLBA). Because the GLBA Privacy Rule keys many of its requirements—such as privacy notices and limits on disclosure to nonaffiliated third parties—to whether data qualifies as NPI, correctly classifying information is a threshold compliance task rather than a formality. Misclassifying data (for example, treating publicly available information as NPI, or overlooking that personally identifiable financial information collected during a transaction is in scope) can lead either to unnecessary restrictions or, more consequentially, to inadequate protection and potential enforcement exposure.
The concept also matters because it is narrower and more specific than the broad privacy vocabulary many practitioners use interchangeably. NPI is a creature of U.S. financial regulation applying to entities that qualify as financial institutions under GLBA; it is not the same as 'personal data' under the EU GDPR, which has different scope, definitions, and territorial reach. Teams operating across jurisdictions can create compliance gaps if they assume a single classification satisfies obligations everywhere. Treating NPI as coextensive with all personal information—or assuming GDPR-style handling automatically satisfies GLBA—risks both over- and under-compliance.
Because the precise contours of NPI depend on how 'personally identifiable financial information' and 'publicly available information' are defined and interpreted, and because these provisions may be amended, the practical stakes lie in the details. Whether a specific data element counts as NPI is fact-specific, and enforcement and interpretation can evolve. Readers should confirm classification decisions against the current text of the GLBA Privacy Rule and applicable guidance rather than relying on general summaries.
Who it's relevant to
Inside NPI
Common questions
Answers to the questions practitioners most commonly ask about NPI.
