Federal & Sector Law

GLBA

Federal financial privacy law. Notice and opt-out before sharing customer data with nonaffiliated third parties; FTC, CFPB and bank regulators enforce.

GLBA requirements

The Gramm-Leach-Bliley Act governs how financial institutions handle nonpublic personal information about their customers, from banks and lenders to insurers, tax preparers and payment apps. Its Privacy Rule (Regulation P) requires a privacy notice and a chance to opt out before that information is shared with nonaffiliated third parties, and it includes the simple fact that someone is a customer or applied for a loan. The Safeguards Rule, updated in 2023, requires a written security program, oversight of service providers, and notice to the FTC within 30 days of a breach affecting 500 or more people. There is no private right of action; the FTC, the CFPB, banking regulators and state insurance regulators enforce it. Most state privacy laws exempt GLBA-covered institutions, so for a bank or fintech the question is whether pixels on login, application and account pages send customer data to ad platforms that are not service providers.

See what your sites and apps actually send

Get a free site analysis: every tracker, mapped to the laws that apply to it.