GLBA
Gramm-Leach-Bliley Act and the FTC Safeguards Rule
Privacy notices and opt-outs for sharing customer financial information, and an information security program with specific safeguards under the Safeguards Rule.
The law in brief
The Gramm-Leach-Bliley Act governs how financial institutions protect and share consumers' personal financial information. In practice it works through two rules: the Privacy Rule, on privacy notices and the right to opt out of certain sharing, and the Safeguards Rule, which requires a written information security program.
"Financial institution" reaches far beyond banks: mortgage brokers, lenders, tax preparers, car dealers that arrange financing and many others are covered, and for them the FTC's rules apply.
Who it applies to
- Financial institutions: businesses significantly engaged in financial activities, such as lending, brokering, advising, insuring or collecting debt.
- Banks and credit unions follow their banking regulators' versions of the rules; most non-bank financial companies follow the FTC's.
- It covers nonpublic personal information about consumers and customers who obtain financial products or services for personal, family or household purposes.
What it requires
A written information security program
Develop, implement and maintain a written program with administrative, technical and physical safeguards appropriate to your size, complexity and the sensitivity of the customer information you hold.
The Safeguards Rule's required elements
Name a qualified individual, base safeguards on a written risk assessment, encrypt customer information, require multi-factor authentication, test continuously or through annual penetration tests and twice-yearly vulnerability scans, train staff, oversee service providers, keep an incident response plan, and report to the board at least annually.
Notify the FTC of security events
Tell the FTC as soon as possible, and no later than 30 days after discovery, of a security event in which unencrypted information of 500 or more consumers was acquired without authorization.
Privacy notices and opt-out
Give customers a clear privacy notice and, before sharing nonpublic personal information with nonaffiliated third parties outside the exceptions, a reasonable chance to opt out.
People's rights
Consumers get a privacy notice explaining what the institution collects and shares, and can opt out of sharing their nonpublic personal information with nonaffiliated third parties, subject to exceptions (Privacy Rule, Regulation P).
Enforcement and penalties
Enforced by the FTC, the Consumer Financial Protection Bureau and the banking regulators, through orders, compliance programs and, depending on the regulator and the violation, civil penalties. Obtaining customer information under false pretenses is a federal crime.
What to do first
- Confirm you are a financial institution and which regulator's rules apply to you.
- Name a qualified individual to run the information security program.
- Run a written risk assessment and build the controls in 16 CFR 314.4 on it.
- Turn on multi-factor authentication and encryption for customer information.
- Oversee service providers by contract and periodic assessment.
- Prepare to notify the FTC of qualifying security events within 30 days.
- Check your privacy notice and opt-out process under the Privacy Rule.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
- FTC Standards for Safeguarding Customer Information (16 CFR Part 314) eCFR · Official text or regulator