Regulations › US federal

GLBA

Gramm-Leach-Bliley Act and the FTC Safeguards Rule

In force financial security
WhenIn effect since 12 November 1999
Who enforces itFTC, CFPB and federal banking regulators
Who it applies toFinancial institutions, broadly defined, including many non-bank lenders, tax preparers and fintechs.

Privacy notices and opt-outs for sharing customer financial information, and an information security program with specific safeguards under the Safeguards Rule.

The law in brief

The Gramm-Leach-Bliley Act governs how financial institutions protect and share consumers' personal financial information. In practice it works through two rules: the Privacy Rule, on privacy notices and the right to opt out of certain sharing, and the Safeguards Rule, which requires a written information security program.

"Financial institution" reaches far beyond banks: mortgage brokers, lenders, tax preparers, car dealers that arrange financing and many others are covered, and for them the FTC's rules apply.

Who it applies to

  • Financial institutions: businesses significantly engaged in financial activities, such as lending, brokering, advising, insuring or collecting debt.
  • Banks and credit unions follow their banking regulators' versions of the rules; most non-bank financial companies follow the FTC's.
  • It covers nonpublic personal information about consumers and customers who obtain financial products or services for personal, family or household purposes.

What it requires

A written information security program

Develop, implement and maintain a written program with administrative, technical and physical safeguards appropriate to your size, complexity and the sensitivity of the customer information you hold.

The Safeguards Rule's required elements

Name a qualified individual, base safeguards on a written risk assessment, encrypt customer information, require multi-factor authentication, test continuously or through annual penetration tests and twice-yearly vulnerability scans, train staff, oversee service providers, keep an incident response plan, and report to the board at least annually.

Notify the FTC of security events

Tell the FTC as soon as possible, and no later than 30 days after discovery, of a security event in which unencrypted information of 500 or more consumers was acquired without authorization.

Privacy notices and opt-out

Give customers a clear privacy notice and, before sharing nonpublic personal information with nonaffiliated third parties outside the exceptions, a reasonable chance to opt out.

People's rights

Consumers get a privacy notice explaining what the institution collects and shares, and can opt out of sharing their nonpublic personal information with nonaffiliated third parties, subject to exceptions (Privacy Rule, Regulation P).

Enforcement and penalties

Enforced by the FTC, the Consumer Financial Protection Bureau and the banking regulators, through orders, compliance programs and, depending on the regulator and the violation, civil penalties. Obtaining customer information under false pretenses is a federal crime.

What to do first

  1. Confirm you are a financial institution and which regulator's rules apply to you.
  2. Name a qualified individual to run the information security program.
  3. Run a written risk assessment and build the controls in 16 CFR 314.4 on it.
  4. Turn on multi-factor authentication and encryption for customer information.
  5. Oversee service providers by contract and periodic assessment.
  6. Prepare to notify the FTC of qualifying security events within 30 days.
  7. Check your privacy notice and opt-out process under the Privacy Rule.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources