What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (2024)

Contact Us Schedule a Demo

Knowledge Center » Data Privacy Automation

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (1)

By Anas Baig | Reviewed By Omer Imran Malik

Published August 3, 2023 / Updated March 12, 2024

Listen to the content

Table of contents

  • Obligations under the GLBA
  • Who is protected under the law?
  • What type of personal information is protected?
  • Penalties
  • Key Facts
  • Key Takeaways
  • Frequently Asked Questions (FAQs)

The Gramm-Leach-Bliley Act (GLBA) or the Financial Services Modernization Act 1999 is a US Federal sectoral legislation that aims to provide increased protections to the privacy of US residents by requiring financial institutions to safeguard the personal information of their customers and to keep customers informed of where that information is being shared.

There are two important rules in relation to the GLBA which impose important obligations on financial institutions (and other entities) to protect and safeguard the privacy of their customers and consumers, they are:

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (2)

GLBA Financial Privacy Rule

  • Covered entities must limit when a "Financial Institution" may disclose a consumer's "nonpublic personal information" to nonaffiliated third parties.
  • The GLBA Financial Privacy Rule applies to businesses that are "significantly engaged" in "financial activities" as described in section 4(k) of the Bank Holding Company Act. "Financial Activities" include:
    • Lending, exchanging, transferring, investing for others, or safeguarding money or securities. These activities cover services offered by lenders, check cashers, wire transfer services, and sellers of money orders.
    • Providing financial, investment or economic advisory services. These activities cover services offered by credit counselors, financial planners, tax preparers, accountants, and investment advisors.
    • Brokering loans.
    • Servicing loans.
    • Debt collecting.
    • Providing real estate settlement services.
    • Career counseling (of individuals seeking employment in the financial services industry).
  • The Privacy Rule protects a consumer's "nonpublic personal information" (NPI). NPI is any "personally identifiable financial information" that a financial institution collects about an individual in connection with providing a financial product or service, unless that information is otherwise "publicly available."
  • Obligations for Financial Institutions under the GLBA Financial Privacy Rule are:
    • Notice: Financial institutions must give their customers - and in some cases their consumers - a "clear and conspicuous" written notice describing their privacy policies and practices. When you provide the notice and what you say depends on what you do with the information.
    • Opt-out right: If you share their NPI with nonaffiliated third parties outside of three exceptions, you must give your consumers and customers an "opt-out notice" that clearly and conspicuously describes their right to opt out of the information being shared 30 days before you share their information. An opt-out notice must be delivered with a privacy notice, and it can be part of the privacy notice.
  • If you receive customer NPI from a non-affiliated financial institution, either under an exception or not, you must ensure it is not used or disclosed for purposes which are not in accordance with original purposes -informed to the customer- for which it was collected and disclosed by the financial institution.
  • The GLBA also prohibits financial institutions from sharing account numbers or similar access numbers or codes for marketing purposes. This prohibition applies even when a consumer or customer has not opted-out of the disclosure of NPI concerning her account. The prohibition applies to disclosures of account numbers for an individual's credit card account, deposit account, or "transaction account" to any nonaffiliated third party to use in telemarketing, direct mail marketing, or any other marketing through electronic mail to the consumer. A "transaction account" is any account to which a third party may initiate a charge.

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (3)

GLBA Safeguards Rule

  • Financial Institutions must protect the private information of customers entrusted in their care
  • “Financial institution” includes many businesses that may not normally describe themselves that way. As per the FTC, the rule applies to all businesses, regardless of size, that are “significantly engaged” in providing financial products or services.
  • Covered entities must implement administrative, technical, or physical safeguards for the use, access, collection, distribution, processing, protection, storage, use, transmission, disposal of, or otherwise handling of customer information.
  • Under the GLBA Safeguards Rule, there must be a written security plan which complements the size and complexity of the covered entity’s business as well as the nature and scope of its activities, and the sensitivity of the customer information it handles.
  • Covered entities are provided flexibility to implement safeguards appropriate to their own circ*mstances, but each company must:
    • ​​Designate one or more employees to coordinate its information security program;
    • Identify and assess the risks to customer information in each relevant area of the company’s operation, and evaluate the effectiveness of the current safeguards for controlling these risks;
    • Design and implement a safeguards program and regularly monitor and test it;
    • Select service providers that can maintain appropriate safeguards, make sure your contract requires them to maintain safeguards, and oversee their handling of customer information; and
    • Evaluate and adjust the program in light of relevant circ*mstances, including changes in the firm’s business or operations, or the results of security testing and monitoring.
  • The Safeguards Rule requires companies to assess and address the risks to customer information in all areas of their operation, including three areas that are particularly important to information security:
    • Employee Management and Training;
    • Information Systems; and
    • Detecting and Managing System Failures.
  • Under Section 501(b) of the GLBA and interagency guidance in 2005, when a financial institution becomes aware of an incident of unauthorized access to sensitive customer information, the institution should conduct a reasonable investigation to promptly determine the likelihood that the information has been or will be misused. If the institution determines that misuse has occurred or is reasonably possible, it should notify the affected customer as soon as possible.
  • Under the GLBA Safeguards rule, a financial institution must conduct assessments to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information.
  • A Financial Institution must also 'oversee service providers' by taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; and requiring by contract that service providers implement and maintain such safeguards.

Obligations under the GLBA

In summary, the GLBA and its associated rules and regulations therefore impose the following responsibilities on financial institutions and other covered entities:

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (7)

Risk Assessments

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (8)

Security Safeguards

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (9)

Data Breach Notifications

Who is protected under the law?

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (10)

Customers

"Customers" are a subclass of consumers who have a continuing relationship with a financial institution. It's the nature of the relationship - not how long it lasts - that defines whether a person is a customer or a consumer.

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (11)

Consumers

A "consumer" is someone who obtains or has obtained a financial product or service from a financial institution that is to be used primarily for personal, family, or household purposes, or that person's legal representative. The term "consumer" does not apply to commercial clients, like sole proprietorships.

What type of personal information is protected?

Nonpublic personal information of customers and includes (but is not limited to):

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (15)

Social Security numbers

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (16)

Credit and income histories

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (17)

Credit and bank card account numbers

NPI does not include information that a financial institution or covered entity has a reasonable basis to believe is lawfully made "publicly available." A covered entity must determine whether:

  1. That the information is generally made lawfully available to the public; and
  2. That the individual can stop the information from being made public and has not done so themselves.

Penalties

GLBA applies to all penalties for noncompliance, including fines and imprisonment. If a financial institution violates GLBA:

  • The institution will be subject to a civil penalty of not more than $100,000 for each violation;
  • Officers and directors of the institution will be subject to, and personally liable for, a civil penalty of not more than $10,000 for each violation;
  • The institution and its officers and directors will also be subject to fines in accordance with Title 18 of the United States Code or imprisonment for not more than five years, or both.

Key Facts

1

Privacy notices under the GLBA Financial Privacy Rule have specific content requirements as well as methods on how these notices must be provided to customers or consumers.

2

GLBA Financial Privacy Rule provides that consumers and customers who have the right to opt out may do so at any time. Once a financial institution receives an opt-out direction from their existing consumers or customers, they must comply with it as soon as is reasonably possible.

3

Exceptions to honoring opt-out requests in GLBA Financial Privacy Rules are applicable when the information-sharing is necessary for processing or administering a financial transaction requested or authorized by a consumer; or to prevent fraud, respond to judicial process or a subpoena, or comply with federal, state, or local laws; or for certain certain “joint” marketing activities.

4

Under the GLBA Safeguards Rule, Financial Insitutitions and covered entities should know where sensitive customer information is stored and store it securely and also limit access to employees who have a business reason to see it.

5

Under a separate rule, the GLBA Disposal Rule, Financial Institutions and covered entities should dispose of customer information in a secure way.

Key Takeaways:

  1. The Gramm-Leach-Bliley Act (GLBA), also known as the Financial Services Modernization Act of 1999, is a pivotal US federal law designed to protect the privacy of consumer information held by financial institutions.
    Here are the key takeaways:
  2. Scope and Application: The GLBA primarily applies to financial institutions engaged in significant financial activities, including lending, investing, advising on financial matters, loan brokering, debt collection, and real estate settlement services, among others.
  3. GLBA Financial Privacy Rule: This rule restricts financial institutions from disclosing a consumer's nonpublic personal information (NPI) to nonaffiliated third parties without consent. NPI encompasses any personally identifiable financial information collected about an individual in connection with any financial product or service.
  4. Consumer Rights under the GLBA:
    - Notice Requirement: Financial institutions must provide clear and conspicuous written notice to their customers and consumers detailing their privacy policies and practices.
    - Opt-out Rights: Consumers and customers must be given the option to opt-out of their NPI being shared with nonaffiliated third parties, except under certain exceptions.
  5. GLBA Safeguards Rule: Financial institutions are mandated to implement comprehensive administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information. This includes having a written security plan, conducting risk assessments, and ensuring third-party service providers also maintain appropriate safeguards.
  6. Data Breach Notifications: In the event of unauthorized access to sensitive customer information, financial institutions are required to investigate promptly and, if misuse of information is confirmed or reasonably possible, notify affected customers as soon as possible.
  7. Penalties for Non-Compliance: Financial institutions that fail to comply with the GLBA may face civil penalties up to $100,000 per violation, while officers and directors may face penalties up to $10,000 per violation. Furthermore, violations can result in fines according to Title 18 of the United States Code or imprisonment for up to five years, or both.
  8. Protected Individuals:
    - Customers: Individuals who have a continuing relationship with a financial institution.
    - Consumers: Individuals who obtain financial products or services for personal, family, or household purposes.
  9. Protected Information: The GLBA protects NPI, which includes but is not limited to names, addresses, social security numbers, credit and income histories, and account numbers. Publicly available information is not considered NPI under the GLBA.
  10. Key Compliance Facts:
    - Privacy notices must meet specific content requirements and be delivered in a manner prescribed by the GLBA.
    - Opt-out rights must be honored promptly upon receipt of a consumer's request.
    - Certain exceptions to opt-out rights exist for necessary information-sharing under specific circ*mstances.
    - Financial institutions must securely store sensitive customer information and restrict access to employees with a business need to know.
  11. Implementation and Enforcement: The GLBA emphasizes the importance of financial institutions knowing where sensitive customer information is stored, securely storing this information, and disposing of it securely in accordance with the GLBA Disposal Rule.

Frequently Asked Questions (FAQs)

The purpose of the GLBA is to enhance the privacy and security of consumers' personal financial information. It mandates financial institutions to protect the confidentiality of this information and provides guidelines for sharing it with nonaffiliated third parties.

Three key rules of the GLBA include:

  1. Privacy Rule: Mandates financial institutions to inform consumers about their information-sharing practices and allow consumers to opt-out of certain information-sharing.
  2. Safeguards Rule: Requires financial institutions to implement measures to secure customer information and protect it from unauthorized access.
  3. Pretexting Provisions: Prohibits the acquisition of personal financial information under false pretenses.

General Data Protection Regulation (GDPR)is a comprehensive data protection regulation in the European Union, focusing on the rights and protection of personal data for EU residents. The Gramm-Leach-Bliley Act (GLBA) is a U.S. law specifically targeting the privacy of consumers' financial information held by financial institutions.

The GLBA is also known as the Gramm-Leach-Bliley Financial Services Modernization Act.

The main purpose of this act is to establish requirements for financial institutions to safeguard customers' nonpublic personal information and provide transparency about their information-sharing practices.

Three key rules of the GLBA include:

  1. Privacy Rule: Ensuring the protection of consumers' personal financial information.
  2. Safeguards Rule: Requiring the establishment of security measures to prevent data breaches.
  3. Pretexting Provisions: Prohibiting deceptive methods of obtaining personal financial information

The Gramm-Leach-Bliley Financial Protection Act, also known as the GLBA, is a federal law in the United States that regulates the privacy and security of consumers' personal financial information held by financial institutions.

An example of this act in action is when a bank informs its customers about its privacy practices, provides them the option to opt-out of certain information sharing, and implements security measures to protect their financial data from unauthorized access or data breaches.

Get all the latest information, law updates and more delivered to your inbox

More Stories that May Interest You

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (18) View More

February 19, 2024

The Role of GLBA Risk Assessment – Safeguarding Customer Data

Understand the role and importance of GLBA risk assessment for financial institutions and the best practices to enable GLBA compliance.

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (19) View More

February 14, 2024

Mastering GLBA Safeguard Rule: Protecting Financial Information

This blog focuses on one of the three important categories discussed in the Act, i.e., the GLBA Safeguards Rule, and how to comply accordingly.

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (20) View More

February 14, 2024

GLBA Compliance Requirements – A Complete Checklist

This GLBA compliance requirements checklist is designed to help you understand the intricacies of GLBA and ensure compliance.

Automating privacy operations across your organization

The multi-disciplinary practice to grow trust-equity of your brand and comply with privacy regulations.

Get the Book

“By leveraging the PrivacyOps constructs from this book across our organization we were able to not only save time and money but also mitigate the risks associated with manual methods of privacy management.”

- Marty Collins, Chief Privacy and Legal Officer, QuinStreet, Inc

At Securiti, our mission is to enable organizations to safely harness the incredible power of Data & AI.

Copyright © 2024 Securiti · Sitemap · XML Sitemap

Newsletter

Company

  • About Us
  • Careers
  • Contact Us
  • Partner Program
  • News Coverage
  • Press Releases

Resources

  • Blog
  • Collateral
  • Knowledge Center
  • Securiti Education
  • Privacy Center
  • Free Do Not Sell Tool
  • What is DSPM

Terms

  • Manage cookie preferences
  • My Privacy Center

Get in touch

[email protected]
Securiti, Inc.
300 Santana Row
Suite 450
San Jose, CA 95128

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (27) What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (31)

What is the Gramm-Leach-Bliley Act (GLBA)? - Securiti (2024)
Top Articles
Liquidity Trap
Should I Apply To Multiple Jobs At The Same Time?
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
Things To Do In Atlanta Tomorrow Night
Non Sequitur
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Otter Bustr
Selly Medaline
Latest Posts
Article information

Author: Kareem Mueller DO

Last Updated:

Views: 6000

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Kareem Mueller DO

Birthday: 1997-01-04

Address: Apt. 156 12935 Runolfsdottir Mission, Greenfort, MN 74384-6749

Phone: +16704982844747

Job: Corporate Administration Planner

Hobby: Mountain biking, Jewelry making, Stone skipping, Lacemaking, Knife making, Scrapbooking, Letterboxing

Introduction: My name is Kareem Mueller DO, I am a vivacious, super, thoughtful, excited, handsome, beautiful, combative person who loves writing and wants to share my knowledge and understanding with you.