9.2 GLBA Privacy Rule, Safeguards Rule, and State Exemptions
Key Takeaways
- The Gramm-Leach-Bliley Act of 1999 Title V covers financial institutions that are significantly engaged in financial activities and protects nonpublic personal information — personally identifiable financial information that is not publicly available.
- The Privacy Rule (CFPB Regulation P, 12 C.F.R. Part 1016) requires a clear privacy notice and an opt-out before sharing nonpublic personal information with nonaffiliated third parties, subject to service-provider/joint-marketing and processing/legal exceptions.
- The FTC Safeguards Rule (16 C.F.R. Part 314, updated 2021 and 2023) requires a written information security program, a Qualified Individual, encryption and multi-factor authentication (or a Qualified Individual-approved alternative), and — as of 13 May 2024 — Federal Trade Commission notice within 30 days of a notification event affecting at least 500 consumers.
- The 5,000-consumer figure in 16 C.F.R. § 314.6 is an exemption from certain program elements (written risk assessment, specified testing, written incident-response plan, annual board report). It is not the breach-notice threshold and it does not excuse the Qualified Individual or the 500-consumer Federal Trade Commission notice.
- Most comprehensive state privacy laws give Gramm-Leach-Bliley Act institutions an entity-level exemption; California's California Consumer Privacy Act / California Privacy Rights Act exemption is narrower and data-level, and the Civil Code § 1798.150 breach private right of action still applies.
9.2 GLBA Privacy Rule, Safeguards Rule, and State Exemptions
The Gramm-Leach-Bliley Act of 1999 (GLBA), Pub. L. 106-102, Title V, is the federal financial-privacy statute. It is not the FCRA. The FCRA regulates consumer reports. GLBA regulates how a financial institution collects, shares, and safeguards nonpublic personal information (NPI) about individuals who obtain financial products or services for personal, family, or household purposes. Title V has two operational halves the exam separates: the Privacy Rule (notice and sharing) and the Safeguards Rule (security).
Who is a financial institution, and what is NPI?
A financial institution is an entity significantly engaged in activities that are financial in nature under Bank Holding Company Act § 4(k). The label is activity-based, not brand-based. Banks, credit unions, and securities firms are in. So are many companies people do not call "banks": mortgage lenders and brokers, payday lenders, finance companies, check cashers, wire transferors, collection agencies, credit counselors, tax preparers, non-federally insured credit unions, investment advisers not required to register with the Securities and Exchange Commission (SEC), and — after the 2021 Safeguards amendments — finders that bring buyers and sellers together. A retailer that issues its own credit card is significantly engaged; a bartender who occasionally runs a tab is not.
NPI is personally identifiable financial information the institution collects in connection with providing a financial product or service, unless the institution has a reasonable basis to believe the information is lawfully publicly available. NPI includes application data (name, Social Security number, income), account numbers and balances, payment history, and the fact of the customer relationship. A list of the institution's own borrowers is NPI even if the phone numbers also appear in a public directory, because the customer relationship is not public. Government records and unrestricted media can be publicly available; an unlisted number is not.
GLBA distinguishes customers from consumers. A consumer obtains a financial product or service for personal, family, or household use (cashing a check, applying for a loan). A customer is a consumer with a continuing relationship (a credit-card account, a mortgage, an advisory relationship). Customers always get an initial privacy notice. Non-customer consumers get a notice only if the institution will share their NPI with nonaffiliated third parties outside the exceptions.
Privacy Rule — CFPB Regulation P
Dodd-Frank transferred most GLBA privacy rulemaking to the CFPB, which recodified the rule as Regulation P, 12 C.F.R. Part 1016. The FTC still maintains 16 C.F.R. Part 313 for entities left with the FTC (notably certain motor-vehicle dealers). Teach Regulation P as the main Privacy Rule text.
The Privacy Rule does three things:
- Notice. Give a clear and conspicuous privacy notice describing the categories of NPI collected, the categories of third parties with whom it is shared, and the consumer's opt-out rights. Customers receive an initial notice when the relationship is established and, historically, an annual notice. The Fixing America's Surface Transportation Act (FAST Act) of 2015 relieved the annual notice if the institution shares only under exceptions that do not trigger an opt-out and has not changed the practices described in the last notice.
- Opt-out. Before disclosing NPI to a nonaffiliated third party outside an exception, the institution must give notice and a reasonable chance to opt out, and must honor that direction. Affiliate sharing is a FCRA (affiliate-marketing) issue more than a GLBA opt-out issue.
- Account-number ban. The institution may not disclose a consumer's account or credit-card number to a nonaffiliated third party for use in telemarketing, direct-mail marketing, or other marketing through electronic mail.
Two exception families matter:
| Exception | Regulation P home | Notice? | Opt-out? | Typical use |
|---|---|---|---|---|
| Service providers and joint marketing (GLBA § 502(b)(2)) | 12 C.F.R. § 1016.13 | Yes (initial notice) | No, if a contract prohibits the third party from using or redisclosing the NPI except to perform the services or joint marketing | Servicers, statement printers, a joint credit-card offer with a retailer |
| Processing, fraud, legal process, CRAs, sale of a business (GLBA § 502(e)) | 12 C.F.R. §§ 1016.14–.15 | Often no separate opt-out notice | No | Completing the consumer's transaction, fraud prevention, subpoena, furnishing to a CRA consistent with the FCRA, a proposed or actual merger |
Scenario. A credit union hires a statement-print vendor and, in a separate deal, sells a marketing list of member names to an unaffiliated auto-insurance agency that is not a joint-marketing partner. The print vendor, under a reuse-limiting contract, fits the service-provider exception: notice, no opt-out. The insurance-list sale is nonaffiliated sharing outside the exceptions: the credit union must have given notice and a reasonable opt-out, and must have waited for that opt-out window, before the sale.
Safeguards Rule — FTC 16 C.F.R. Part 314
The Safeguards Rule implements GLBA's security mandate for financial institutions under FTC jurisdiction (nonbank institutions that another GLBA regulator does not examine). Banks follow interagency security guidelines, not Part 314, but CIPP/US items that say "Safeguards Rule" mean the FTC rule. The original 2003 rule was principle-based. The FTC amended it in 2021 (most new elements effective 9 June 2023) and added breach notification in 2023 (effective 13 May 2024).
Covered institutions must develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards appropriate to size, complexity, activities, and the sensitivity of customer information. The program's objectives are confidentiality, protection against anticipated threats, and protection against unauthorized access that could cause substantial harm or inconvenience.
Section 314.4 now lists concrete elements. The ones the exam names most often:
- Designate a Qualified Individual to implement and supervise the program. The person needs real-world competence, not a named degree. A service provider may serve, but the institution must designate a senior employee to oversee that provider.
- Conduct a written risk assessment and periodic reassessments.
- Implement safeguards, including access controls, a data and system inventory, encryption of customer information at rest and in transit (or effective alternative controls the Qualified Individual approves), application-security review, multi-factor authentication (MFA) for anyone accessing customer information (knowledge, possession, or inherence — unless the Qualified Individual approves an equivalent in writing), secure disposal generally no later than two years after last use to serve the customer, change management, and logging of authorized-user activity.
- Regularly monitor and test. Continuous monitoring or annual penetration testing plus vulnerability assessments at least every six months.
- Oversee service providers by selection, contract, and periodic assessment.
- Maintain a written incident-response plan.
- Require the Qualified Individual to report in writing, at least annually, to the board or equivalent governing body.
Two numbers candidates collapse: 500 and 5,000
Verify the current text before you pick a threshold.
Notification event — 500 consumers, 30 days. 16 C.F.R. § 314.4(j) requires the institution to notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event: unauthorized acquisition of unencrypted customer information of at least 500 consumers. Encrypted data counts as unencrypted if the encryption key was also accessed. Unauthorized access is treated as unauthorized acquisition unless reliable evidence shows acquisition did not and could not reasonably have occurred. The report goes through the FTC's online form and includes the institution's identity, dates, number of consumers affected or potentially affected, types of information, and a brief description. This duty took effect 13 May 2024. It is not a consumer-notice statute and it is not a 5,000-person trigger.
Small-institution exemption — 5,000 consumers. 16 C.F.R. § 314.6 says §§ 314.4(b)(1), (d)(2), (h), and (i) do not apply to institutions that maintain customer information concerning fewer than 5,000 consumers. Those four citations are the written risk assessment, the specified penetration-test / vulnerability-assessment alternative, the written incident-response plan, and the annual written board report. The exemption does not drop the written program, the Qualified Individual, encryption, MFA, service-provider oversight, or the 500-consumer FTC notice.
State comprehensive-law exemptions — California is narrower
Most comprehensive state privacy laws enacted after 2018 give GLBA-covered institutions an entity-level exemption: if you are a financial institution (or affiliate) subject to GLBA Title V, the state law does not apply to you. Some states layer a data-level exemption as well (NPI processed in compliance with GLBA is out even if the entity is otherwise in).
California is the exam's narrower case. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), exempts personal information collected, processed, sold, or disclosed pursuant to GLBA — a data-level exemption. The bank itself is not carved out as an entity. Employee data, business-to-business contacts, website-visitor identifiers, and marketing files that are not NPI can still be CCPA personal information. The exemption does not apply to Civil Code § 1798.150, the private right of action for certain data breaches involving nonencrypted and nonredacted sensitive information. A California bank can therefore be out of CCPA access/delete/opt-out for its mortgage NPI and still face a 1798.150 suit after a credentials breach.
Exam traps. Do not apply the FCRA opt-out to GLBA sharing, or the GLBA opt-out to a consumer-report pull. Do not say GLBA is opt-in. Do not treat the 5,000-consumer Safeguards exemption as the FTC notice threshold. Do not give California banks a full entity-level holiday from the CCPA.
A credit union wants to send member names and account-relationship flags to two outside parties: a statement-print vendor under a contract that limits reuse, and an unaffiliated sporting-goods retailer that will mail catalog offers. No joint-marketing agreement exists with the retailer. What does Regulation P require?
A nonbank mortgage lender subject to the Federal Trade Commission Safeguards Rule discovers unauthorized acquisition of unencrypted customer information about 800 consumers. The lender maintains information on 4,200 consumers in total. What does the current Rule require?
A national bank subject to the Gramm-Leach-Bliley Act also runs a non-financial lifestyle app that collects California residents' geolocation and browsing data. Which statement about California's comprehensive privacy law is accurate?