GLBA requirements
The Gramm-Leach-Bliley Act governs how financial institutions handle nonpublic personal information about their customers, from banks and lenders to insurers, tax preparers and payment apps. Its Privacy Rule (Regulation P) requires a privacy notice and a chance to opt out before that information is shared with nonaffiliated third parties, and it includes the simple fact that someone is a customer or applied for a loan. The Safeguards Rule, updated in 2023, requires a written security program, oversight of service providers, and notice to the FTC within 30 days of a breach affecting 500 or more people. There is no private right of action; the FTC, the CFPB, banking regulators and state insurance regulators enforce it. Most state privacy laws exempt GLBA-covered institutions, so for a bank or fintech the question is whether pixels on login, application and account pages send customer data to ad platforms that are not service providers.
Other Federal & Sector Laws
See what your sites and apps actually send
Get a free site analysis: every tracker, mapped to the laws that apply to it.