ATLAS/BRIEFINGLaw, organized for consequential decisions.

FIN-02 Financial Regulation & Digital Assets How Money Moves Federal

GLBA Privacy Notices and the Safeguards Rule for Financial Technology Companies

GLBA runs on two tracks that are often confused: what you must tell customers about data sharing, and what you must build to protect the data. This brief separates them and lists what each demands.

Technical diagram marking this brief's subject

Briefing in 60 seconds

  1. Coverage turns on activity, not on holding a bank charter. A company significantly engaged in financial activities can be a financial institution under GLBA.
  2. The privacy track requires an initial notice, an opt-out where nonaffiliated sharing triggers one, and an annual notice unless a statutory exception applies.
  3. The Safeguards Rule requires a written program with a named qualified individual, risk assessment, access controls, encryption, MFA, monitoring, training, and vendor oversight.
  4. Since 2024, covered non-bank institutions must notify the FTC of a qualifying security event affecting at least 500 consumers, generally within 30 days of discovery.

Controlling variables

Status
Whether the company is significantly engaged in financial activities and therefore a covered financial institution, and whether its regulator is the FTC or a banking agency.
Facts
How many consumers the company maintains information on. A sub-5,000 threshold exempts an institution from several written-program requirements, not from the rule itself.
Documents
Whether the security program, risk assessment, incident response plan, and annual report to the board exist in writing. Undocumented practice is treated as absent.
Timing
When a security event was discovered. The FTC notification window runs from discovery, not from completion of the forensic investigation.
Jurisdiction
Federal GLBA duties sit on top of state breach notification statutes and state privacy laws, which have their own triggers, deadlines, and recipients.

General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.

Two different obligations live under the Gramm-Leach-Bliley Act, and companies routinely satisfy one while ignoring the other. The privacy track governs disclosure: what a company tells consumers about the information it collects and shares, and when they can opt out. The security track — the Safeguards Rule — governs protection, and it is prescriptive in a way most privacy law is not.

The threshold question comes first, because it surprises people. GLBA coverage depends on what a company does, not on whether it calls itself a bank.

Are you a financial institution?

A financial institution under GLBA is a business significantly engaged in financial activities, drawing on the activities framework of the Bank Holding Company Act. That reaches far past depository institutions. Lenders and loan servicers, mortgage brokers, payment and money transmission businesses, debt collectors, tax preparers, certain investment advisers, credit counselors, and — following the 2021 amendments to the rule's definitions — "finders" who bring buyers and sellers of financial products together, can all land inside it.

The data at issue is nonpublic personal information: personally identifiable financial information a consumer provides, that results from a transaction, or that the institution otherwise obtains in connection with providing a financial product or service. The Safeguards Rule uses a related but broader operational concept, customer information, covering records containing that information about a customer, in any form, held by the institution or on its behalf.

That last phrase — or on its behalf — is why vendor management is a compliance obligation rather than a procurement preference. Data sitting in a third-party processor's environment remains the institution's responsibility.

The privacy track: notices and opt-outs

The privacy rule requires an initial privacy notice at the time a customer relationship is established, describing the categories of information collected and disclosed, the categories of parties it goes to, and the institution's confidentiality and security practices. Where the institution shares nonpublic personal information with nonaffiliated third parties outside the statutory exceptions, consumers must receive a clear opt-out notice and a reasonable means to exercise it.

Annual notices are required while the customer relationship continues, subject to an exception added by statute: an institution that neither shares in a way that triggers an opt-out right nor has changed its policies since the last notice may skip the annual delivery. Exceptions also permit sharing with service providers and joint marketing partners under contract, and sharing necessary to process and service transactions the consumer requested.

For most non-bank companies the privacy rule now runs through the CFPB's Regulation P, while the FTC retains the Safeguards Rule and privacy authority over the entities left in its lane. The practical answer is to identify the regulator before drafting the notice, because the model form and the rule citations differ.

Check who regulates you: privacy notice obligations sit with different agencies depending on the institution type. Building a notice from a template written for a different regulator produces a document that cites rules that do not govern you.

The safeguards track: what the written program must contain

The Safeguards Rule, as amended in 2021 with the substantive elements taking effect in June 2023, requires a written information security program appropriate to the institution's size, complexity, and the sensitivity of the information it holds. The rule then names the elements. This is the part that cannot be satisfied by a general commitment to security.

Required elements of the information security program and the artifact each should produce
ElementWhat the rule expectsArtifact to keep
Qualified individualA single named person responsible for overseeing and enforcing the program, whether internal or supplied by a vendorWritten designation, scope of authority, reporting line
Risk assessmentA written assessment identifying reasonably foreseeable internal and external risks, with criteria for evaluating and addressing themDated assessment plus the remediation decisions it drove
Data inventoryIdentification of where customer information is collected, stored, and transmitted across systems and vendorsCurrent inventory and data flow map
Access controlsTechnical and physical controls limiting access to what each role actually needs, reviewed periodicallyRole definitions and periodic access review records
EncryptionEncryption of customer information in transit over external networks and at rest, or an effective alternative approved in writing by the qualified individualEncryption standards document, or the written approval of the alternative
Multi-factor authenticationMFA for any individual accessing an information system holding customer information, unless a written equivalent control is approvedMFA coverage report and exception approvals
Monitoring and testingContinuous monitoring, or periodic penetration testing plus vulnerability assessments at defined intervalsTest reports and remediation tracking
TrainingSecurity awareness training for personnel and skills verification for security staffAttendance and completion records by role
Service provider oversightSelection based on capability, contractual safeguards obligations, and periodic reassessmentDiligence file, contract clauses, reassessment notes
Incident response planA written plan covering goals, roles, internal processes, communications, documentation, and post-incident revisionCurrent plan plus records of any exercise or activation
Secure disposal and change managementDisposal of customer information no longer needed, generally within two years of last use, and controlled system change proceduresRetention schedule and change management records
Annual reportA written report from the qualified individual to the board or a senior officer on program status and material mattersThe report itself, with evidence it was delivered

A partial exemption exists for institutions maintaining customer information concerning fewer than 5,000 consumers. That exemption relieves the written risk assessment, the incident response plan, the annual report, and the continuous monitoring or penetration testing requirements. It does not exempt the institution from the rule, and a growing company can cross the threshold without noticing.

Notification events and the FTC filing

The 2023 amendment adding a reporting duty took effect in May 2024. Covered non-bank financial institutions must notify the FTC of a notification event — the acquisition of unencrypted customer information without the authorization of the individual it concerns — involving the information of at least 500 consumers. Notice is due as soon as possible and generally no later than 30 days after discovery, filed through the FTC's online mechanism.

Three details drive the operational design. The clock runs from discovery, not from forensic certainty, so the incident response plan needs a defined moment at which discovery is deemed to occur. The encryption safe harbor fails if the encryption key was also accessed by an unauthorized person. And the report is published by the FTC, which makes accuracy and phrasing a matter for counsel rather than for the security team alone.

The federal filing does not displace state breach notification statutes, which have their own definitions of covered data, their own deadlines, and their own recipients including state attorneys general. Sequencing all of these — while keeping the forensic work inside a privileged investigation where that is available — is covered in data-breach response: privilege, notification deadlines, and regulator notice.

  • Program exists only as slides. A deck describing security posture is not a written information security program. Regulators read for the named elements, and absence of a document is treated as absence of the control.
  • Qualified individual unnamed. Distributing the role across a security committee satisfies nobody. Name a person, in writing, with defined authority.
  • MFA gaps at the edges. Contractor accounts, service accounts, and legacy admin consoles are where coverage reports usually break, and where incidents usually start.
  • Vendors accepted on a security questionnaire alone. The rule expects contractual safeguards obligations and periodic reassessment, not a one-time answer at onboarding.
  • Discovery undefined. Without a written trigger for when an event is discovered, the 30-day clock is argued about after the fact rather than managed during the incident.
  • Retention drift. Customer information kept indefinitely enlarges every future incident. Disposal schedules are a security control, not a storage-cost measure.

Questions the desk gets

We are a software vendor, not a lender. Are we covered?

Possibly not directly, but the analysis is about activities rather than labels, and a company that originates, brokers, services, collects, or facilitates financial products may be significantly engaged in financial activities. Even where a vendor is not itself covered, its financial-institution customers must impose safeguards obligations by contract and reassess the vendor periodically. In practice the obligations arrive either way — as a rule, or as a contract term you cannot negotiate away.

Does encryption remove the notification duty?

Only where the information was genuinely protected by encryption at the moment it was acquired. The notification duty attaches to acquisition of unencrypted customer information, and the protection is lost if the encryption key was accessed by an unauthorized person. Treat the safe harbor as a factual question to be answered by the forensic record — key management, scope of encryption at rest, and what the intruder actually reached — not as a default assumption based on a policy statement.

How does this interact with our AI vendors?

Any vendor that processes customer information is a service provider for Safeguards purposes, including model providers and analytics tools. That means selection diligence, contractual safeguards obligations, and periodic reassessment. Whether the vendor may use your data to improve its models is a separate contract question with its own risk profile, addressed in the brief on contracting with AI vendors.

Is there overlap with dispute and complaint handling?

Yes, operationally. Error and dispute files hold concentrated nonpublic personal information — account numbers, identity documents, transaction histories — and are frequently stored in support tooling outside the main data inventory. The handling obligations for those disputes are set out in Regulation E error resolution, and the systems holding them belong in the Safeguards data inventory.

Does GLBA cover employee data?

The rules protect information about consumers and customers obtained in connection with providing financial products or services. Employee records are generally governed by other law, including state privacy and biometric statutes that carry their own consent and retention rules — see biometric privacy laws. Companies nonetheless tend to protect both under one program, because separating the data sets in practice is harder than applying a single control standard.

How to use this brief

Run the coverage question first and write down the answer with reasons; every later decision depends on it. Then treat the elements table as a gap list rather than a reading exercise — for each row, identify the artifact that exists today, and where none does, name an owner and a date. The rows with no artifact are the findings a regulator or an acquirer will surface anyway.

Separately, pressure-test the discovery trigger and the 30-day path before an incident, not during one. Read 16 CFR 314.4 against your own program document and the FTC's GLBA business guidance for the current compliance expectations. Entity-level transparency obligations that often land on the same compliance calendar are covered in beneficial ownership reporting.

Sources

  1. FTC — Gramm-Leach-Bliley Act business guidance
  2. Cornell LII — 15 U.S.C. 6801 (protection of nonpublic personal information)
  3. Cornell LII — 16 CFR 314.4 (elements of the information security program)
  4. FTC — Privacy and Security business guidance
  5. CFPB — Regulation P, 12 CFR Part 1016 (privacy of consumer financial information)

Atlas Research Desk

ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.