What It Is

The Gramm-Leach-Bliley Act (GLBA) is a U.S. federal law that governs how financial institutions protect customers' nonpublic personal information (NPI). It was enacted as Public Law 106-102 and is codified at 15 U.S.C. §6801 et seq.

GLBA's protections work through two implementing rules and one set of statutory provisions:

  • Financial Privacy Rule: requires institutions to explain how customer information is collected, shared, and protected - including the customer's right to opt out of sharing NPI with nonaffiliated third parties (FTC).
  • Safeguards Rule: requires a written information security program to protect NPI (16 CFR Part 314).
  • Pretexting provisions: the statute itself (15 U.S.C. §§6821-6827) prohibits obtaining customer financial information by false pretenses. There is no separate "Pretexting Rule" - these protections are statutory, not regulatory.

From a practical standpoint, the Safeguards Rule drives most IT and cybersecurity requirements.

What Information Is Regulated

GLBA protects nonpublic personal information (NPI). NPI is any personally identifiable financial information a consumer provides to obtain a financial product or service.

That includes:

  • Names, addresses, and contact information: when collected in a financial relationship.
  • Social Security numbers: the highest-value target in most breaches.
  • Bank account and routing numbers: the keys to moving money.
  • Credit and debit card data: overlapping with PCI DSS scope.
  • Loan, credit, and transaction records: account histories and balances.
  • Tax and income information: returns, W-2s, and supporting documents.
  • Anything a consumer provides to get a financial product or service: the catch-all that makes NPI broad.

From an IT perspective, NPI usually exists across multiple systems at once. That sprawl is what makes access control and data protection the center of GLBA work.

IT Requirements

GLBA does not mandate specific technologies. It requires reasonable safeguards based on risk - and the Safeguards Rule makes those expectations concrete.

In practice, GLBA compliance requires:

Risk assessments and a security program. Written risk assessments are explicitly required under the FTC Safeguards Rule, which implements GLBA (16 CFR 314.4(b)). That means documented identification of threats and vulnerabilities, a formal information security program, and ongoing risk management - not a one-time exercise.

Access controls and identity management. Role-based access, least-privilege permissions, multi-factor authentication (MFA), secure remote access, and regular access reviews. Access to NPI should track job function, nothing more.

Data protection and encryption. Encryption of NPI at rest and in transit, secure storage and backups, protection against unauthorized disclosure, and secure disposal when data is no longer needed.

Monitoring, logging, and incident response. Logging of access to sensitive data, monitoring for suspicious activity, documented incident response and breach-handling procedures, and records of incidents and remediation.

Vendor and third-party risk management. The Safeguards Rule explicitly requires covered institutions to assess service providers, contract for safeguards, and maintain oversight of third-party security practices (16 CFR 314.4(f)). You remain responsible for NPI - even when vendors are involved.

How It Fits Into Cyber Risk Management

GLBA aligns closely with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, SOC 2, and the FTC Safeguards Rule requirements it operates through.

Organizations that follow these frameworks are typically well positioned to meet GLBA expectations. The same fundamentals - risk assessment, access control, encryption, monitoring, vendor oversight - satisfy all of them at once.

That is the practical argument for managing GLBA inside a broader cyber risk program instead of as a standalone checklist.

How We Help With GLBA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps where NPI lives in your environment and evaluates your safeguards against the FTC Safeguards Rule requirements that implement GLBA.

How to Prepare

  1. Identify where NPI exists

    Document the systems storing customer financial data, the data flows between them, who has access, and which vendors are involved. You cannot protect data you have not located.

  2. Perform a risk assessment

    Assess threats (phishing, ransomware, insider risk), vulnerabilities (misconfigurations, outdated systems), likelihood and impact, and mitigation steps. Written risk assessments are explicitly required under the FTC Safeguards Rule, which implements GLBA (16 CFR 314.4(b)).

  3. Implement or strengthen core security controls

    At minimum: MFA for systems accessing NPI, encryption of data and backups, endpoint and email security, logging and monitoring, and secure remote access.

  4. Formalize policies and procedures

    GLBA compliance requires documented information security policies, incident response plans, vendor management procedures, and access control policies. Policies must reflect actual system behavior - not aspirations.

  5. Manage vendor and third-party risk

    Confirm contracts include security requirements, vendors are assessed regularly, and their access is limited and monitored. Flow-down oversight is your obligation under 16 CFR 314.4(f).

  6. Train employees

    Staff should understand what counts as customer information, how to protect it, how to recognize social engineering attempts, and how to report incidents. Human error remains a major GLBA risk factor.

GLBA in Florida

GLBA sets the federal floor. Florida adds a second layer: the Florida Information Protection Act, F.S. 501.171, applies to any commercial entity that acquires or maintains Floridians' personal information - including financial institutions already regulated under GLBA.

  • A state security mandate of its own: F.S. 501.171(2) requires reasonable measures to protect and secure personal information in electronic form. This obligation exists independently of your federal compliance.
  • 30-day breach notification: affected individuals must be notified no later than 30 days after determining a breach occurred. Breaches affecting 500 or more Florida residents must also be reported to the Florida Department of Legal Affairs within 30 days, with a possible 15-day extension for good cause (F.S. 501.171(3)-(4)).
  • The federal-regulator bridge: if you notify individuals under the rules of your primary or functional federal regulator - your GLBA-side obligation - Florida deems you compliant with its individual-notice requirement, provided you timely give a copy of that notice to the department (F.S. 501.171(4)(g)). One coordinated notice can satisfy both layers.
  • Vendors are on a 10-day clock: third-party agents holding your customer data must notify you within 10 days of determining a breach (F.S. 501.171(6)). Put that deadline in your vendor contracts.
  • Real penalties for late notice: violations are treated as unfair or deceptive trade practices, with civil penalties of $1,000 per day for the first 30 days, $50,000 per subsequent 30-day period, and a $500,000 cap (F.S. 501.171(9)).

The Treasure Coast runs on exactly the businesses GLBA reaches - financial advisors, CPA and tax firms, mortgage and title offices serving Martin, St. Lucie, and Palm Beach counties. If that is you, both layers above are your problem, and both are manageable.

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25