Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Data Types & Classification

Nonpublic Personal Information

Also known as: NPI, Non-Public Personal Information, Nonpublic personal information under GLBA
Simply put

Nonpublic Personal Information (NPI) is personal financial information that a financial institution collects about a consumer and that is not publicly available. It generally includes information a consumer provides when obtaining a financial product or service, and it must be protected from unauthorized disclosure. NPI is a concept specific to U.S. financial privacy law rather than a universal privacy term.

Formal definition

Under the U.S. Gramm-Leach-Bliley Act (GLBA) and its implementing Privacy Rule, Nonpublic Personal Information (NPI) generally means personally identifiable financial information that is not publicly available, obtained by a financial institution in connection with offering or delivering a financial product or service to an individual for personal, family, or household purposes. NPI centers on 'personally identifiable financial information'—for example, information a consumer supplies on an application or that arises from a transaction—and is distinct from information lawfully made available to the public. The term is defined by regulation and applies to entities that qualify as financial institutions under GLBA within the United States; it should not be conflated with broader privacy-law concepts such as 'personal data' under the EU GDPR, which has different scope and definitions. Application to specific data elements and entities is fact-specific, and readers should verify the precise definition and any exclusions against the current text of the GLBA Privacy Rule and related guidance, as regulatory provisions may be amended.

Why it matters

Nonpublic Personal Information sits at the center of U.S. financial privacy obligations under the Gramm-Leach-Bliley Act (GLBA). Because the GLBA Privacy Rule keys many of its requirements—such as privacy notices and limits on disclosure to nonaffiliated third parties—to whether data qualifies as NPI, correctly classifying information is a threshold compliance task rather than a formality. Misclassifying data (for example, treating publicly available information as NPI, or overlooking that personally identifiable financial information collected during a transaction is in scope) can lead either to unnecessary restrictions or, more consequentially, to inadequate protection and potential enforcement exposure.

The concept also matters because it is narrower and more specific than the broad privacy vocabulary many practitioners use interchangeably. NPI is a creature of U.S. financial regulation applying to entities that qualify as financial institutions under GLBA; it is not the same as 'personal data' under the EU GDPR, which has different scope, definitions, and territorial reach. Teams operating across jurisdictions can create compliance gaps if they assume a single classification satisfies obligations everywhere. Treating NPI as coextensive with all personal information—or assuming GDPR-style handling automatically satisfies GLBA—risks both over- and under-compliance.

Because the precise contours of NPI depend on how 'personally identifiable financial information' and 'publicly available information' are defined and interpreted, and because these provisions may be amended, the practical stakes lie in the details. Whether a specific data element counts as NPI is fact-specific, and enforcement and interpretation can evolve. Readers should confirm classification decisions against the current text of the GLBA Privacy Rule and applicable guidance rather than relying on general summaries.

Who it's relevant to

Compliance officers at financial institutions
Professionals responsible for GLBA compliance need to determine whether their organization qualifies as a financial institution and which data elements it holds constitute NPI. Accurate classification underpins privacy notice practices and limits on disclosure. Because scope is fact-specific and provisions may be amended, classification decisions should be verified against the current GLBA Privacy Rule.
Data protection and privacy specialists operating across jurisdictions
Specialists managing programs that span the U.S. and other regions should keep NPI distinct from broader concepts such as GDPR 'personal data,' which differ in scope, definition, and territorial reach. Assuming one classification or handling standard satisfies all regimes can create gaps; obligations must be mapped separately to each applicable framework.
Information security teams
Teams tasked with safeguarding customer data rely on knowing which information is NPI to apply appropriate protections against unauthorized disclosure. While security controls implement the protection expectations tied to NPI, the underlying legal classification is distinct from security engineering and should be confirmed with compliance and legal counsel.
Auditors and assessors
Those evaluating a financial institution's privacy posture use the NPI definition as a scoping reference for what data falls under GLBA Privacy Rule obligations. Because interpretation of 'personally identifiable financial information' and 'publicly available information' can be nuanced and evolving, findings should reference the current regulatory text rather than general summaries.
Legal counsel advising covered entities
Counsel advising organizations that may qualify as financial institutions under GLBA need to assess, on the specific facts, whether data elements are NPI and how any exclusions apply. This entry is informational only; application to particular circumstances requires professional judgment and review of the latest authoritative source.

Inside NPI

Personally Identifiable Financial Information
Information a consumer provides to a financial institution to obtain a product or service, information resulting from a transaction involving a financial product or service, or information otherwise obtained in connection with providing such a product or service. This is the core category of NPI under the U.S. Gramm-Leach-Bliley Act (GLBA).
Consumer-Provided Data
Details supplied directly by an individual, such as account balances, income, Social Security numbers, or application information, when the purpose is to obtain a financial product or service. Readers should verify the precise scope against the current text of the GLBA and its implementing regulations.
Transaction-Derived Information
Data generated through the customer relationship, including transaction histories, payment records, and account activity associated with a financial product or service.
Lists, Descriptions, and Groupings
Any list, description, or other grouping of consumers (and publicly available information pertaining to them) that is derived using nonpublic personal information generally falls within the definition.
Exclusion of Publicly Available Information
Information that is lawfully made available from government records, widely distributed media, or legally required disclosures is generally treated as outside the scope of NPI in most cases, though the treatment depends on how the information was obtained and combined.

Common questions

Answers to the questions practitioners most commonly ask about NPI.

Is Nonpublic Personal Information (NPI) the same as personally identifiable information (PII) under privacy laws generally?
No. NPI is a defined term specific to the U.S. financial-privacy context under the Gramm-Leach-Bliley Act (GLBA) framework, and it should not be treated as interchangeable with the broader concept of personally identifiable information used in other regimes. PII is a more general term appearing across many U.S. sectoral rules and guidance, while related concepts such as "personal data" under the EU GDPR carry their own distinct definitions and scope. Because these terms arise from different legal instruments and jurisdictions, an item may fall within one definition but not another. Readers should map data against the specific definition applicable to the regime they are subject to rather than assuming equivalence, and verify against the current official text.
If information is publicly available, does that automatically mean it is not NPI?
Not necessarily. The public-availability exception is narrower and more fact-specific than it may first appear, and whether information counts as publicly available generally depends on conditions set out in the applicable rules rather than on a simple judgment that the data is "out there." The manner in which information was obtained and whether there is a reasonable basis to believe it is lawfully made available to the general public can affect the analysis. Because interpretation turns on the specific facts and the current text, organizations should not assume that data is outside the NPI definition merely because a version of it appears in some public source. Verify the treatment against the applicable official text and apply professional judgment to the particular facts.
How should an organization identify which of its data holdings may qualify as NPI?
As an informational matter, organizations generally begin by inventorying the data they collect and hold in connection with covered financial products or services, then assessing each category against the applicable statutory and regulatory definition of NPI. This typically involves distinguishing information obtained from customers or in the course of providing a financial product or service from information that may meet a public-availability exception. Because the analysis is fact-specific and depends on how data was obtained and used, mapping should be documented and revisited as data practices change. This description is informational only; application to a particular organization's holdings requires professional judgment and review against the current official text.
What role does NPI classification play in privacy notices?
Classifying data as NPI can inform the content of privacy notices that covered entities may be required to provide, because such notices generally describe categories of information collected and disclosed and any sharing practices. Accurately identifying what constitutes NPI helps an organization describe its practices consistently with the applicable rules. However, notice obligations, their timing, and their required content are governed by the specific regulatory requirements applicable to the entity, which differ by sector and may be subject to change. Organizations should confirm the precise notice requirements against the current authoritative source and treat this as an informational overview rather than tailored guidance.
How does NPI classification affect decisions about sharing data with third parties?
Whether and how NPI may be shared with third parties generally depends on the applicable rules, which may distinguish between affiliated and nonaffiliated parties and may condition certain disclosures on notice or the opportunity to opt out, subject to defined exceptions. Correctly identifying data as NPI is a prerequisite to applying these sharing provisions accurately. Because the specific conditions, exceptions, and opt-out mechanics are set by the governing regulatory text and can vary, organizations should evaluate each disclosure against the current requirements. This is an informational description and not advice for any particular sharing arrangement, which requires professional judgment.
How should NPI be considered within an information security program?
Identifying NPI within data holdings can help an organization scope safeguards intended to protect the confidentiality, integrity, and availability of that information, and NPI is often a focus of applicable data-protection safeguard expectations in the financial-privacy context. It is worth keeping the privacy classification of data separate from the security controls applied to it: NPI describes a category of information, while security measures are the operational and technical means of protecting it. The specific safeguard obligations, and how they scale with risk and organizational circumstances, are governed by the applicable rules and may evolve. Verify current requirements against the authoritative source and apply professional judgment to your environment.

Common misconceptions

NPI is a universal privacy term that applies the same way across all jurisdictions and sectors.
NPI is a concept defined under the U.S. Gramm-Leach-Bliley Act, which governs financial institutions in the United States. It is distinct from broader terms such as 'personal data' under the EU GDPR or 'personal information' under various U.S. state laws, each of which has its own scope and definition. Do not treat NPI as interchangeable with these other concepts.
Any personal data held by a financial institution automatically qualifies as NPI.
The GLBA concept generally centers on information connected to obtaining or providing a financial product or service. Information that is lawfully publicly available is generally excluded in most cases, and whether specific data qualifies is fact-specific and depends on how it was collected and used.
Complying with GLBA privacy provisions covering NPI means an organization has met all its privacy and security obligations.
Handling NPI under GLBA is one set of obligations and does not by itself satisfy security requirements, other sectoral rules, or the requirements of other jurisdictions. Privacy and security are distinct disciplines, and additional laws or contractual standards may apply depending on the data and the organization.

Best practices

Confirm whether your organization meets the definition of a 'financial institution' under the GLBA before applying NPI obligations, since scope is fact-specific and may not be obvious.
Maintain a documented data inventory that distinguishes NPI from publicly available information and from personal data governed by other regimes, so that each category receives the appropriate handling.
Verify the precise scope of NPI, applicable exclusions, and any notice or safeguarding requirements against the current official text of the GLBA and its implementing regulations rather than relying on summaries.
Treat privacy obligations for NPI and information security safeguards as separate but complementary workstreams, and confirm that both are addressed rather than assuming one covers the other.
Assess whether other jurisdictional or sectoral rules apply in parallel to the same data, and reconcile any differing definitions and requirements before finalizing controls.
Engage qualified legal or compliance professionals to apply these definitions to your specific circumstances, as application to particular facts requires professional judgment.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.