9.4 Online Banking Privacy and M&A Diligence

Key Takeaways

  • Online-banking privacy on the CIPP/US exam is still Gramm-Leach-Bliley Act NPI plus Safeguards controls: biometrics are an inherence authentication factor, third-party tracking on bank properties can share NPI or create a Regulation P issue, and customer information must be encrypted and multi-factor authenticated.
  • Data aggregators and 'open banking' do not repeal the Gramm-Leach-Bliley Act. Screen-scraping or an application-programming-interface share of account data is still a disclosure of nonpublic personal information that needs an exception, consent, or a compliant opt-out path.
  • Dodd-Frank § 1033 directed a personal-financial-data-rights rule. The Consumer Financial Protection Bureau finalized a rule in October 2024, but as of August 2026 a federal court has enjoined enforcement and the Bureau is reconsidering the rule — do not treat April 2026 compliance dates as live.
  • In a financial-services merger or acquisition, inventory the personal information in the deal, run cybersecurity diligence, and plan for successor liability. Gramm-Leach-Bliley Act § 502(e) lets parties share NPI for a proposed or actual sale of the business, but a material change in sharing practices still requires a revised notice and a new opt-out before the new sharing begins.
  • Deal documents should use representations, indemnities, escrow or holdback, and, where the risk warrants it, a reverse-termination right keyed to an undisclosed incident.
Last updated: August 2026

9.4 Online Banking Privacy and M&A Diligence

Body of Knowledge 2.6.1 closes II.C with online banking (biometrics, third-party tracking, data security) and merger-and-acquisition (M&A) diligence. There is no separate "Internet Bank Act." The exam expects you to apply GLBA, the Safeguards Rule, the FCRA, and ordinary deal mechanics to a digital channel and to a transaction.

Biometrics, tracking, and security in the online channel

Retail banks and nonbank lenders collect more than account numbers online. They collect device identifiers, behavioral telemetry, chat transcripts, and — increasingly — biometrics used to unlock an app or to prove the customer is present.

Biometrics (fingerprint, face, voice, behavioral gait) are an inherence factor under the Safeguards Rule's MFA definition: access to customer information must use at least two of knowledge, possession, and inherence, unless the Qualified Individual approves an equivalent control in writing. Using a face-print to open the app does not, by itself, satisfy GLBA. The institution still needs a written program, encryption of customer information at rest and in transit, access control, logging, and service-provider oversight of the biometrics vendor. Biometric templates are NPI when collected in connection with the financial product. They may also be biometric identifiers under state laws taught in Domain V (Illinois Biometric Information Privacy Act (BIPA) is the private-right-of-action example). GLBA does not preempt a BIPA notice-and-consent claim about a bank's Illinois face-scan.

Third-party tracking is the pixel, software-development kit, or analytics tag on a public bank site, authenticated dashboard, or mobile app. If the tag sends account status, authenticated-user identifiers, or other NPI to an advertising platform, the bank has made a nonaffiliated disclosure. Regulation P then asks the ordinary questions: is there a service-provider contract that limits reuse, a § 502(e) exception, customer consent, or a completed opt-out cycle? "Everyone uses analytics" is not an exception. Tracking on authenticated pages is the higher-risk fact pattern, because the payload more often includes NPI rather than mere marketing cookies. The FTC and CFPB have treated misleading "we do not share" statements about pixels as UDAP / UDAAP problems even when a candidate hoped GLBA would be the only statute in the file.

Data security in the online channel is the Safeguards Rule applied to apps and application programming interfaces (APIs): inventory where customer information lives, encrypt it, require MFA, test (continuous monitoring or annual penetration tests plus six-month vulnerability scans), log authorized access, and oversee processors. Card data may also sit under PCI DSS by contract; PCI is not a substitute for GLBA, as Domain I already established.

Aggregators, screen-scraping, and open banking versus GLBA

Data aggregators (account-linking services that feed budgeting apps, payment apps, and lenders) historically obtained credentials and screen-scraped the bank site, or used a customer-authorized API. Either way, the bank that discloses NPI and the aggregator that receives it have GLBA issues.

  • The customer's act of entering credentials or clicking "connect my bank" can be consent under GLBA § 502(e), but the consent must be knowing enough to be real. A buried pre-checked box is a UDAAP fact pattern waiting to happen.
  • If the bank sends NPI to the aggregator as a service provider to the bank, Regulation P § 1016.13 requires a reuse-limiting contract. Most aggregator relationships are the customer's service, not the bank's, so that exception often does not fit.
  • The aggregator that receives NPI is limited in reuse and redisclosure. It does not become free to sell the account-level file to marketers.
  • If the aggregator assembles the data to furnish consumer reports to lenders, it may also be a CRA, and the FCRA — not only GLBA — applies.

Dodd-Frank § 1033 (12 U.S.C. § 5533) says a covered person must, subject to rules the CFPB prescribes, make available to a consumer information in the covered person's control or possession concerning the consumer financial product or service that the consumer obtained. That is the statutory hook for open banking / personal financial data rights. The CFPB issued a final rule in October 2024 with staggered compliance that would have begun 1 April 2026 for the largest data providers. As of August 2026, teach the current status, not the hoped-for calendar: a federal court has enjoined the CFPB from enforcing the 2024 rule (E.D. Ky., 29 October 2025), the underlying litigation is stayed while the Bureau reconsiders, an appeal is pending in the Sixth Circuit, and the Bureau issued an August 2025 Advance Notice of Proposed Rulemaking to reconsider who may act as a consumer's representative, whether data providers may charge fees, and the security and privacy cost-benefit picture. The statute is still on the books. The 2024 implementing rule is not a live compliance date. GLBA still governs any NPI that actually moves.

Scenario. A customer authorizes a budgeting app to read 12 months of transactions. The bank can share that NPI with the customer's authorized agent, but it must still authenticate the request, log it, and stay inside the customer's authorization. The aggregator may not resell the transaction stream to a data broker. If the 2024 § 1033 rule is still enjoined on exam day, the right answer is GLBA + contract + consent, not "section 1033 already requires a free, standardized API to every developer."

M&A diligence — privacy as a deal term

Financial-services deals move loan files, core-processor extracts, employee data, marketing lists, and security-incident histories. CIPP/US expects a diligence checklist, not a corporate-finance lecture.

1. Inventory the personal information. Map what NPI, consumer-report information, employee data, and biometric or tracking data each entity holds; where it lives (including vendors); the legal regime for each pile (GLBA, FCRA, CCPA data-level remainder, state biometrics); and whether any pile is out of contract or out of notice. You cannot negotiate a representation you have not scoped.

2. Cybersecurity and incident diligence. Review Safeguards and Red Flags programs, Qualified Individual reports, penetration-test results, vendor inventories, prior notification events, regulator correspondence, and cyber-insurance claims. Ask whether encryption keys sat with the data that was accessed. An undisclosed 800-consumer notification event is both a Safeguards problem and a purchase-price problem.

3. Successor liability. The buyer of a financial institution or a loan portfolio generally steps into the seller's GLBA, FCRA, UDAAP, consent-order, and state-law exposure for the business it continues. Asset deals do not automatically wash liability for the files the buyer takes and uses. Consent orders and look-back restitution can travel with the book.

4. Sharing authority for the deal itself. GLBA § 502(e) / Regulation P § 1016.15 permits disclosing NPI in connection with a proposed or actual sale, merger, transfer, or exchange of all or a portion of a business or operating unit, if the NPI concerns solely consumers of that business or unit. That exception gets the data room open. It does not authorize the buyer to adopt new nonaffiliated sharing (for example, selling the acquired customer list to the buyer's retail affiliate network) without looking at notice and opt-out.

5. Notice of a change in privacy practices. If the surviving institution will share NPI in a new way that is not an exception, it must send a revised privacy notice and a new reasonable opt-out and wait before the new sharing. "We bought the bank, so the old notice covers whatever we do next" is wrong. If practices are unchanged and the FAST Act annual-notice exception still fits, a special deal-closing mailer may be unnecessary — but that is a facts question, not a default.

6. Contractual risk allocation. Representations and warranties should cover compliance with GLBA, FCRA, Red Flags, Safeguards, and the absence of undisclosed notification events or AG/CFPB investigations. Indemnities should survive closing for pre-close incidents. An escrow or purchase-price holdback funds unknown but likely claims. A reverse-termination right (buyer may walk, sometimes with a fee paid to the buyer) is the nuclear option when diligence reveals a material, previously undisclosed incident or an unfixable consent-order problem. None of those tools replaces a revised privacy notice to customers.

Diligence itemWhy it is on the CIPP/US list
PI inventoryYou cannot apply GLBA, FCRA, or a state data-level exemption to a pile you have not identified
Cyber / Safeguards file500-consumer FTC notice, encryption, MFA, and vendor gaps become the buyer's problem on day one
Successor liabilityUsing the acquired files continues the legal duties attached to those files
§ 502(e) deal exceptionOpens the data room; does not rewrite post-close sharing
Revised notice / new opt-outRequired before new nonaffiliated sharing that is not excepted
Escrow, indemnity, reverse terminationAllocate unknown-incident risk; they do not satisfy customer-notice law

Exam traps. Do not invent a live, enforceable 2024 § 1033 compliance date in 2026. Do not treat aggregator access as outside GLBA. Do not say a merger exception permanently waives customer opt-out rights after closing. Do not confuse a reverse-termination fee with a privacy notice.

Loading diagram...
Financial-Services Deal: NPI Path from Diligence to Close
Test Your Knowledge

A budgeting app asks customers to enter online-banking credentials so the app can screen-scrape transaction history. Which statement is accurate under current federal financial-privacy law?

A
B
C
D
Test Your Knowledge

A bank plans to add facial recognition to its mobile-deposit flow and to place a third-party advertising pixel on the authenticated dashboard that transmits account-status flags. Which compliance framing matches the Body of Knowledge?

A
B
C
D
Test Your Knowledge

A buyer is acquiring a nonbank lender and will, after closing, start selling the acquired customer list to unaffiliated insurance agencies — sharing the seller never described and never offered an opt-out for. Diligence also finds an unreported 900-consumer Safeguards notification event. What is the sound privacy structure?

A
B
C
D