GLBA Compliance
Gramm-Leach-Bliley Act — Financial Data Privacy for Every Firm That Handles Customer Financial Information
lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned
WHAT IS GLBA?
GLBA requires financial institutions to protect customer financial information. Full stop.
The Gramm-Leach-Bliley Act (GLBA) is a federal law enacted in 1999 that requires financial institutions — broadly defined — to explain their information-sharing practices to customers and to protect sensitive customer data. GLBA establishes three principal rules: the Financial Privacy Rule, the Safeguards Rule, and the Pretexting Protection provisions. For most Sacramento small businesses in financial services, the Privacy Rule and Safeguards Rule are the operative compliance obligations.
While GLBA predates many modern cybersecurity frameworks, the FTC’s 2023 update to the Safeguards Rule — the primary implementing regulation for GLBA’s information security requirements — significantly modernized and strengthened its requirements. GLBA compliance today means meeting the current Safeguards Rule standard, which includes prescriptive technical controls that did not exist in the original statute.
1999
GLBA enacted
2023
Safeguards Rule updated
3
principal GLBA rules
$100K+
per violation for institutions
THE THREE GLBA RULES
What each rule requires of your business.
Rule
Requirement
Financial Privacy Rule
Requires financial institutions to provide customers with a privacy notice at the time of the relationship and annually thereafter, explaining what information is collected, how it is used, and with whom it is shared. Gives customers the right to opt out of certain sharing with non-affiliated third parties.
Safeguards Rule (FTC)
Requires financial institutions to develop, implement, and maintain a written information security program protecting customer nonpublic personal information (NPI). The 2023 update added specific technical requirements including MFA, encryption, monitoring, and designated security leadership.
Pretexting Protection
Prohibits obtaining or disclosing customer financial information through false pretenses — including social engineering, impersonation, and deceptive means. Institutions must implement controls to verify the identity of those requesting access to customer accounts.
WHO GLBA APPLIES TO
A broader scope than most realize.
GLBA defines ‘financial institution’ as any company that is ‘significantly engaged’ in financial activities. Courts and regulators have interpreted this broadly to include businesses that go well beyond traditional banking:
Banks, credit unions, and savings institutions
Mortgage lenders and brokers
Insurance companies and agencies
Securities broker-dealers and investment advisors
CPA firms and tax preparers handling financial account data
Check cashing and payday lending businesses
Retailers that offer store credit or financing
Auto dealers that extend or arrange financing
Importantly, GLBA also imposes obligations on ‘service providers’ — companies that receive customer financial information from financial institutions in order to provide services. IT providers, cloud vendors, and third-party processors who handle NPI on behalf of a financial institution must implement appropriate safeguards under their service agreements.
KEY GLBA COMPLIANCE REQUIREMENTS
What your information security program must address.
Requirement
What It Means in Practice
Designate a program coordinator
Appoint a qualified individual responsible for the information security program (may be outsourced to a service provider)
Conduct a risk assessment
Identify reasonably foreseeable internal and external risks to NPI security; evaluate sufficiency of existing safeguards
Design safeguards
Implement controls in response to identified risks, across employee training, information systems, and third-party oversight
Monitor and test
Regularly test and monitor systems and procedures; evaluate and adjust the program based on results
Oversee service providers
Select service providers with appropriate safeguards; ensure contracts require them to maintain NPI security; periodically assess compliance
Adjust the program
Update the program in response to business changes, new risks, test results, and regulatory developments
Annual board reporting
Report to the Board of Directors (or equivalent) at least annually on the information security program
Respond to incidents
Implement a written incident response plan; notify the FTC within 30 days of qualifying events affecting 500+ customers
PENALTIES
Enforcement consequences for non-compliant financial institutions.
CIVIL PENALTY EXPOSURE FOR INSTITUTIONS
Up to $100,000 per violation
Financial institutions face civil money penalties from federal regulators. Officers and directors can face personal liability of up to $10,000 per violation. Criminal penalties apply for knowing violations.
HOW LBT DELIVERS GLBA COMPLIANCE
End-to-end program management for financial services firms.
✓ Information Security Program Development
Build and document a written GLBA-compliant information security program covering risk assessment, safeguard implementation, vendor oversight, testing, monitoring, and program updates.
✓ Privacy Notice Review & Compliance
Review and update customer privacy notices to ensure they accurately describe data collection, use, and sharing practices, and satisfy the Financial Privacy Rule’s timing and delivery requirements.
✓ Pretexting Controls Implementation
Implement technical and procedural controls to verify the identity of individuals requesting access to customer account information — including authentication protocols, call center procedures, and social engineering awareness training.
✓ Vendor Contract Review & Oversight
Review service provider agreements for GLBA-required security provisions and establish an ongoing vendor oversight process to verify that third parties maintaining NPI continue to meet appropriate standards.
✓ Annual Board Reporting
Prepare the required annual written report to senior management or the board summarizing the state of the information security program, identified risks, and corrective actions taken.
✓ FTC Incident Notification Support
In the event of a qualifying data breach, support the required FTC notification within 30 days and manage communications with affected customers as required.
Is Your Business GLBA Ready?
Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.
BOOK YOUR FREE GLBA ASSESSMENT →
+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California
© 2026 LBT Technology Group, LLC · GLBA Compliance Services · Sacramento, CA · Confidential
