AuditXYZ

Compliance Framework

Gramm-Leach-Bliley Act (Financial Services Modernization Act of 1999) (GLBA)

The Gramm-Leach-Bliley Act requires financial institutions to protect consumer financial data. This guide covers the Safeguards Rule, Privacy Rule, and the 2023 FTC updates with practical compliance steps.

$25,000–$300,0003–9 monthsAudit Required1999 (with 2023 FTC Safeguards Rule update)
Issuing BodyUnited States Congress / Federal Trade Commission (FTC)
First Published1999-11-12
Latest Version1999 (with 2023 FTC Safeguards Rule update)
Typical Cost$25,000–$300,000
Typical Timeline3–9 months
Audit RequiredYes
Audit FrequencyAnnual risk assessment required. Examination frequency depends on regulatory agency and institution risk profile.
Geographyunited-states

GLBA: Gramm-Leach-Bliley Act Compliance Guide

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices and safeguard sensitive consumer data. Originally enacted in 1999, GLBA received a significant update in 2023 when the FTC revised the Safeguards Rule to impose more specific, prescriptive security requirements on non-banking financial institutions. For any company that broadly qualifies as a "financial institution" — a definition far wider than most businesses realize — GLBA compliance is not optional.

What GLBA Is and Who Issues It

GLBA was signed into law in November 1999, replacing Depression-era laws that had separated banking, securities, and insurance activities. The Act is implemented by multiple federal regulators: the FTC enforces GLBA for non-banking financial institutions, while banking regulators (OCC, Federal Reserve, FDIC, NCUA) oversee banks and credit unions under their own implementing regulations.

The FTC's updated Safeguards Rule, which took effect June 9, 2023, represents the most significant enhancement to GLBA since its original enactment. The rule replaced a general, principles-based security standard with specific, prescriptive requirements — bringing non-banking financial institutions substantially closer to bank-level security expectations.

Who Must Comply

GLBA applies broadly to "financial institutions" — a definition that extends well beyond banks and brokerage firms. Under the FTC's jurisdiction, the following businesses must comply with the Safeguards Rule:

  • Mortgage brokers and mortgage lenders
  • Payday lenders and consumer finance companies
  • Auto dealers that arrange or facilitate financing
  • Tax preparation and filing services
  • Debt collectors
  • Credit counseling services
  • Financial advisors and investment advisors not registered with the SEC
  • Insurance agents and underwriters
  • Real estate settlement services
  • Retailers that extend credit through their own credit cards
  • Finders (companies that connect buyers and sellers of financial products)

Banking regulators use substantially similar rules to oversee banks, thrifts, and credit unions. The FTC is the primary regulator for the diverse non-banking sector, making GLBA compliance a priority for fintech companies, tax technology platforms, and many professional services firms that interact with consumer financial data.

The Three Core Components

The Financial Privacy Rule

The Privacy Rule requires financial institutions to provide customers with clear, conspicuous notices explaining what nonpublic personal information (NPI) is collected, how it is used, and with whom it is shared. These privacy notices must be provided at the time a customer relationship is established and annually thereafter.

Customers must be given the opportunity to opt out of certain information sharing with non-affiliated third parties. Institutions that share NPI with affiliates for marketing purposes face additional notice and opt-out requirements. The notice must be written in plain language and cover all categories of NPI collected and all material sharing practices.

The Safeguards Rule (Updated 2023)

The 2023 Safeguards Rule transformed GLBA from a framework-based requirement into a prescriptive standard with specific technical controls. Key requirements now include:

  • Qualified Individual: Designate a qualified individual responsible for overseeing, implementing, and enforcing the information security program. This person need not be a full-time CISO but must have the necessary qualifications and authority.
  • Risk Assessment: Conduct a written risk assessment identifying reasonably foreseeable internal and external risks to customer information security. The assessment must be reviewed and updated regularly and when circumstances change.
  • Access Controls: Implement access controls based on least-privilege principles, including multi-factor authentication (MFA) for any individual accessing customer information systems from a remote location or any system that contains customer information.
  • Encryption: Encrypt all customer information held or transmitted by the institution, both in transit and at rest. Exceptions require documented risk analysis justifying alternative compensating controls.
  • Secure Development: Implement secure development practices and conduct testing of security controls.
  • Multi-Factor Authentication: MFA is now explicitly required — not merely recommended — for system access. The rule specifies that MFA or an equivalent must be used for any individual accessing customer information systems.
  • Penetration Testing: Conduct continuous monitoring or periodic penetration testing and vulnerability assessments. Annual penetration testing is explicitly required.
  • Security Events Monitoring: Implement monitoring and logging of authorized users' activities and access to customer information.
  • Incident Response Plan: Develop and implement a written incident response plan that addresses goals, roles, communications, and post-incident analysis.
  • Vendor Oversight: Select and retain service providers that maintain appropriate safeguards and require service provider contracts to include security requirements.
  • Annual Reporting: The qualified individual must report in writing to the board of directors or equivalent body at least annually on the status of the information security program.

Pretexting Protection

The Pretexting provisions prohibit the use of false pretenses to obtain customer financial information. This covers social engineering attacks where fraudsters impersonate customers to obtain their financial data from institutions. Institutions must implement authentication procedures that prevent pretexting, and employees must be trained to recognize and resist social engineering attempts.

Audit and Assessment Process

GLBA does not require a formal third-party certification like SOC 2 or PCI DSS. Instead, compliance is demonstrated through:

  • Annual risk assessment documentation
  • Written information security program
  • Annual board/leadership report from the qualified individual
  • Regulatory examination by the FTC or applicable banking regulator

The FTC conducts examinations of non-banking financial institutions, typically triggered by complaints, data breaches, or as part of sweep examinations of industries with elevated risk profiles. Banking regulators conduct periodic safety-and-soundness examinations that include GLBA compliance assessment.

A data breach affecting 500 or more customers must be reported to the FTC within 30 days of discovery under a notification requirement added by the FTC in 2023. This reporting obligation is a significant operational requirement that demands a mature incident response capability.

Costs and Timeline

Organization TypeTypical TimelineEstimated Cost Range
Small financial institution (under 500 employees)3–5 months$25,000–$75,000
Mid-sized non-bank lender5–7 months$75,000–$150,000
Large multi-line financial institution7–9 months$150,000–$300,000

Ongoing annual costs include risk assessment updates, penetration testing ($15,000–$50,000), security awareness training, and the qualified individual's time.

GLBA overlaps meaningfully with several other frameworks, making a multi-framework approach practical:

  • NIST CSF: Approximately 65% overlap. NIST CSF provides a governance structure that maps well onto GLBA's Safeguards Rule requirements. Organizations using NIST CSF can demonstrate GLBA compliance more readily by mapping CSF subcategories to Safeguards Rule elements.
  • ISO 27001: About 50% overlap, primarily in risk assessment, access controls, and incident management. ISO 27001 certification does not satisfy GLBA but demonstrates a mature security posture to regulators.
  • SOX: For public financial institutions subject to both SOX and GLBA, the IT general controls required for SOX ICFR overlap with GLBA Safeguards Rule controls around access management and change management. See the SOX guide.
  • AML/BSA: GLBA's customer data protection requirements operate alongside AML/BSA's Know Your Customer obligations. Both apply to most financial institutions simultaneously. See the AML/BSA guide.
  • PCI DSS: Financial institutions processing card payments must comply with both GLBA and PCI DSS. The overlap is limited (around 30%) but both share encryption and access control requirements.

How Automation Helps

GLBA's Safeguards Rule now resembles a technical security standard more than a principles-based compliance framework — making automation directly applicable:

  • Automated access reviews ensure that user access to customer information systems is reviewed periodically and excess access is removed
  • Continuous monitoring tools track anomalous access to customer data and surface security events for incident response
  • Policy management platforms maintain the written information security program with current versions and annual review workflows
  • Vendor risk management modules track Safeguards Rule compliance of service providers and flag contract renewal gaps

LowerPlane supports GLBA Safeguards Rule compliance with AI-powered evidence collection, continuous control monitoring, and vendor management workflows across 50-plus frameworks. Starting at $4,000 per year with a free tier, LowerPlane is rated 9.4/10 on AuditXYZ. Fintech companies managing both GLBA and PCI DSS or SOC 2 programs find significant efficiency gains from a unified platform. Review the compliance automation landscape for a full comparison.

Frequently Asked Questions

Does GLBA apply to my fintech company?

It may. If your company provides financial services in the US and handles nonpublic personal information about consumers — including names combined with financial account numbers, income data, or payment information — you may qualify as a "financial institution" under GLBA's broad definition. Companies that originate loans, process payments, provide tax services, arrange financing, or offer credit counseling are typically in scope. Consult legal counsel to determine applicability based on your specific business model.

What counts as "nonpublic personal information" under GLBA?

NPI is any personally identifiable financial information that is not publicly available. This includes financial account numbers, credit scores, income information, payment history, and information provided in connection with obtaining a financial product or service. It also includes any list or description derived from such information. Information that consumers voluntarily make publicly available (such as a public social media profile) is generally not NPI.

What are the penalties for GLBA non-compliance?

The FTC can impose civil penalties of up to $50,120 per violation per day for violations of the Safeguards Rule. Financial institutions may also face civil lawsuits from affected consumers following a data breach. Banking regulators can issue cease-and-desist orders and impose supervisory requirements on non-compliant banks. The reputational and customer trust damage from a publicized breach or regulatory action often exceeds the direct financial penalties.

Do I need to appoint a full-time CISO for GLBA compliance?

No. The Safeguards Rule requires a "qualified individual" responsible for the information security program, but this does not need to be a full-time Chief Information Security Officer. The qualified individual can be an employee with other responsibilities, an outsourced service provider, or a fractional CISO, provided they have the necessary expertise and authority to implement the program. The key requirement is that this person reports annually in writing to the board or equivalent governing body.

How does the 2023 Safeguards Rule change what I was already doing?

The 2023 update moved GLBA from a principles-based standard to a prescriptive one. Organizations that had a mature information security program will find many requirements already met. The primary new obligations for most organizations are: explicit MFA requirements, mandatory annual penetration testing, the board reporting requirement from a designated qualified individual, and the 30-day breach notification to the FTC for breaches affecting 500 or more customers. Organizations operating under pre-2023 compliance programs should conduct a gap assessment against the updated rule.

Request a GLBA consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

NIST CSFMedium65%
ISO 27001Medium50%

Related frameworks

Get matched with a GLBA auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.