GLBA
15 U.S.C. §§ 6801–6809; 16 C.F.R. Parts 313, 314Gramm-Leach-Bliley Act — Privacy Rule and Safeguards Rule
In force since July 1, 2001
Who it applies to
- Financial institutions: entities significantly engaged in financial activities, broadly defined
- Reaches mortgage brokers, auto dealers arranging finance, tax preparers and debt collectors, not only banks
Consumer rights
- Access / know — not granted
- Correction — not granted
- Deletion / erasure — not granted
- Portability — not granted
- Opt out of sale / sharing — grantedStop the business selling or sharing your personal data with third parties.
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — not granted
Obligations
- Consent model
- Opt-out
- Universal opt-out signal
- Not required
- Risk assessments
- Required for higher-risk processing
- Data protection officer
- Required
- Records of processing
- Not required
- Processor contract
- Required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
Breach notification
- To individuals
- Set by state law; the federal rule addresses the regulator
- To the regulator
- To the FTC as soon as possible and no later than 30 days after discovery, for events affecting 500 or more consumers
- What triggers it
- Unauthorised acquisition of unencrypted customer information
Penalties
- Headline
- FTC Act enforcement, plus banking-regulator supervisory action
- Private right of action
- No — enforcement is by the regulator only
- Notes
- The GLBA opt-out is weak by modern standards: it covers sharing with non-affiliated third parties and does not reach affiliate sharing, which is why the CCPA's GLBA carve-out is so consequential.
Exemptions
Data
- Information about businesses rather than individuals
Amendment history
June 9, 2023
Amended Safeguards Rule
Added prescriptive security requirements including access controls, encryption, multi-factor authentication and a named qualified individual.
May 13, 2024
Safeguards Rule breach notification
Requires non-banking financial institutions to notify the FTC of security events affecting 500 or more consumers.
Sources
- PrimaryRegulation16 C.F.R. Part 314 — Safeguards Rule
- OfficialRegulatorFTC — Gramm-Leach-Bliley Act guidance