GLBA is often misread as a policy or legal problem. In practice, GLBA compliance is driven almost entirely by cybersecurity controls, risk management, and vendor oversight.
If your organization handles sensitive financial information, even indirectly, GLBA compliance is a security obligation, not just a regulatory one.
The Gramm-Leach-Bliley Act (GLBA) is a U.S. federal law that governs how financial institutions protect customers' nonpublic personal information (NPI). It was enacted as Public Law 106-102 and is codified at 15 U.S.C. §6801 et seq.
GLBA's protections work through two implementing rules and one set of statutory provisions:
From a practical standpoint, the Safeguards Rule drives most IT and cybersecurity requirements.
GLBA applies to financial institutions, broadly defined: any institution whose business is "engaging in an activity that is financial in nature or incidental to such financial activities" (16 CFR 314.2(h)). That definition includes far more than banks.
Covered organizations include:
Service providers sit one step removed. A vendor that receives customer financial data is not itself a covered financial institution unless its own business is financial in nature. GLBA reaches vendors through flow-down instead: covered institutions must select capable providers, contract for safeguards, and periodically assess them (16 CFR 314.4(f)).
If your organization collects, processes, stores, or transmits customer financial information, GLBA likely applies - directly, or through your customers' contracts.
GLBA protects nonpublic personal information (NPI). NPI is any personally identifiable financial information a consumer provides to obtain a financial product or service.
That includes:
From an IT perspective, NPI usually exists across multiple systems at once. That sprawl is what makes access control and data protection the center of GLBA work.
Three layers govern financial data security, and each answers a different question.
GLBA is the law - it establishes the legal obligation to protect customer information. The FTC Safeguards Rule is the how - it defines the minimum security program regulators expect. FFIEC guidance is how regulators test it - banking examiners use it to evaluate whether controls actually work.
Understanding which layer you are answering to keeps compliance work focused instead of duplicated.
GLBA does not mandate specific technologies. It requires reasonable safeguards based on risk - and the Safeguards Rule makes those expectations concrete.
In practice, GLBA compliance requires:
Risk assessments and a security program. Written risk assessments are explicitly required under the FTC Safeguards Rule, which implements GLBA (16 CFR 314.4(b)). That means documented identification of threats and vulnerabilities, a formal information security program, and ongoing risk management - not a one-time exercise.
Access controls and identity management. Role-based access, least-privilege permissions, multi-factor authentication (MFA), secure remote access, and regular access reviews. Access to NPI should track job function, nothing more.
Data protection and encryption. Encryption of NPI at rest and in transit, secure storage and backups, protection against unauthorized disclosure, and secure disposal when data is no longer needed.
Monitoring, logging, and incident response. Logging of access to sensitive data, monitoring for suspicious activity, documented incident response and breach-handling procedures, and records of incidents and remediation.
Vendor and third-party risk management. The Safeguards Rule explicitly requires covered institutions to assess service providers, contract for safeguards, and maintain oversight of third-party security practices (16 CFR 314.4(f)). You remain responsible for NPI - even when vendors are involved.
GLBA is actively enforced. The FTC has brought numerous GLBA enforcement actions, and the amended Safeguards Rule expanded expectations around risk assessments, MFA, encryption, qualified security leadership, continuous monitoring, and incident reporting.
Failures often result in:
GLBA aligns closely with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, SOC 2, and the FTC Safeguards Rule requirements it operates through.
Organizations that follow these frameworks are typically well positioned to meet GLBA expectations. The same fundamentals - risk assessment, access control, encryption, monitoring, vendor oversight - satisfy all of them at once.
That is the practical argument for managing GLBA inside a broader cyber risk program instead of as a standalone checklist.
Here is the key takeaway: GLBA compliance is largely about doing basic cybersecurity well - and proving it.
Enforcement actions frequently cite the same gaps: missing risk assessments, weak access controls, lack of encryption, poor vendor oversight, and inadequate incident response.
Strong fundamentals dramatically reduce exposure. The work is not exotic; it is disciplined.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment maps where NPI lives in your environment and evaluates your safeguards against the FTC Safeguards Rule requirements that implement GLBA.
Document the systems storing customer financial data, the data flows between them, who has access, and which vendors are involved. You cannot protect data you have not located.
Assess threats (phishing, ransomware, insider risk), vulnerabilities (misconfigurations, outdated systems), likelihood and impact, and mitigation steps. Written risk assessments are explicitly required under the FTC Safeguards Rule, which implements GLBA (16 CFR 314.4(b)).
At minimum: MFA for systems accessing NPI, encryption of data and backups, endpoint and email security, logging and monitoring, and secure remote access.
GLBA compliance requires documented information security policies, incident response plans, vendor management procedures, and access control policies. Policies must reflect actual system behavior - not aspirations.
Confirm contracts include security requirements, vendors are assessed regularly, and their access is limited and monitored. Flow-down oversight is your obligation under 16 CFR 314.4(f).
Staff should understand what counts as customer information, how to protect it, how to recognize social engineering attempts, and how to report incidents. Human error remains a major GLBA risk factor.
If your business is financial in nature - lending, advising, insuring, preparing taxes, collecting debts, or processing financial transactions - GLBA almost certainly applies. The definition of "financial institution" is far broader than banks (16 CFR 314.2(h)). If you are a vendor to a covered institution, the obligations reach you through your customer contracts instead.
NPI is personally identifiable financial information a consumer provides to obtain a financial product or service - names and contact details in a financial relationship, Social Security numbers, account and routing numbers, card data, loan and transaction records, and tax information. If a consumer gave it to you to get a financial service, treat it as NPI.
GLBA is the law; the Safeguards Rule is the regulation that implements its security requirements. GLBA establishes the obligation to protect customer information. The Safeguards Rule (16 CFR Part 314) defines the written security program, controls, and accountability regulators expect. Most day-to-day GLBA security work is actually Safeguards Rule work.
Yes. Under the Financial Privacy Rule, institutions must explain what information they collect and how they share it - and customers have the right to opt out of sharing NPI with nonaffiliated third parties. Privacy notices and opt-out mechanics are compliance obligations, not courtesies.
The FTC has brought numerous enforcement actions under GLBA and the Safeguards Rule. Consequences include investigations, consent orders, court-ordered relief, and long-term regulatory oversight - plus the reputational and insurance costs that follow a public action.
Not directly, in most cases. A service provider is only a covered financial institution if its own business is financial in nature. But you must select capable providers, require safeguards by contract, and periodically assess them (16 CFR 314.4(f)) - and you remain responsible for the NPI they hold.
It depends on your environment - how many systems hold NPI, what controls already exist, and how much documentation needs to be built. We publish no pricing because honest numbers require that context. Firm quote before any work begins. The conversation costs nothing.
Start by knowing where you stand. Our Cyber Risk & Compliance Gap Assessment maps your NPI exposure, evaluates your safeguards against the requirements that apply, and gives you a prioritized roadmap - before a regulator or an incident forces the issue.
GLBA sets the federal floor. Florida adds a second layer: the Florida Information Protection Act, F.S. 501.171, applies to any commercial entity that acquires or maintains Floridians' personal information - including financial institutions already regulated under GLBA.
The Treasure Coast runs on exactly the businesses GLBA reaches - financial advisors, CPA and tax firms, mortgage and title offices serving Martin, St. Lucie, and Palm Beach counties. If that is you, both layers above are your problem, and both are manageable.
Official source: Federal Trade Commission
Secondary source: U.S. Code, 15 U.S.C. Chapter 94
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25