GLBA

15 U.S.C. §§ 6801–6809; 16 C.F.R. Parts 313, 314

Gramm-Leach-Bliley Act — Privacy Rule and Safeguards Rule

In force since July 1, 2001

Who it applies to

  • Financial institutions: entities significantly engaged in financial activities, broadly defined
  • Reaches mortgage brokers, auto dealers arranging finance, tax preparers and debt collectors, not only banks

Consumer rights

  • Access / know — not granted
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — grantedStop the business selling or sharing your personal data with third parties.
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — not granted

Obligations

Consent model
Opt-out
Universal opt-out signal
Not required
Risk assessments
Required for higher-risk processing
Data protection officer
Required
Records of processing
Not required
Processor contract
Required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
Set by state law; the federal rule addresses the regulator
To the regulator
To the FTC as soon as possible and no later than 30 days after discovery, for events affecting 500 or more consumers
What triggers it
Unauthorised acquisition of unencrypted customer information

Penalties

Headline
FTC Act enforcement, plus banking-regulator supervisory action
Private right of action
No — enforcement is by the regulator only
Notes
The GLBA opt-out is weak by modern standards: it covers sharing with non-affiliated third parties and does not reach affiliate sharing, which is why the CCPA's GLBA carve-out is so consequential.

Exemptions

Data

  • Information about businesses rather than individuals

Amendment history

  1. June 9, 2023

    Amended Safeguards Rule

    Added prescriptive security requirements including access controls, encryption, multi-factor authentication and a named qualified individual.

  2. May 13, 2024

    Safeguards Rule breach notification

    Requires non-banking financial institutions to notify the FTC of security events affecting 500 or more consumers.

Sources

Timeline

todayGLBA in forceJuly 1, 2001Amended Safeguards RuleJune 9, 2023Safeguards Rule breach notificationMay 13, 2024