Compliance · Financial institutions

Gramm-Leach-Bliley Act (GLBA) of 1999

The Gramm-Leach-Bliley Act requires "financial institutions" to protect the privacy and security of their customers' personal financial information. The definition is broad: it covers not just banks and credit unions, but any business significantly engaged in financial activities.

Who it applies to

  • Banks, credit unions and savings institutions
  • Mortgage brokers, lenders and loan servicers
  • Insurance agencies
  • Accountants, tax preparers and financial advisors
  • Car dealers that arrange financing
  • Check-cashing and payday-loan businesses
  • Real estate settlement services and collection agencies

What it requires

GLBA has two main pieces. The Privacy Rule governs what you tell customers about how their information is shared. The Safeguards Rule, enforced by the Federal Trade Commission and updated in 2023, requires a written information security program with a named person in charge, risk assessments, employee training, and oversight of service providers.

The updated Safeguards Rule speaks directly to disposal: customer information must be securely destroyed no later than two years after it was last used, unless it's needed for a legitimate business purpose or required by law. It also requires you to oversee the vendors who handle that information.

What non-compliance costs

GLBA violations are handled by the FTC and banking regulators. Penalties can reach tens of thousands of dollars per violation, per day, and enforcement actions typically come with multi-year monitoring and mandatory security programs. In the PLS Financial case on our case studies page, dumping loan applications in a dumpster drew both GLBA Safeguards Rule and Disposal Rule charges.

This page is a plain-English summary for business owners, not legal advice. Talk to your attorney or compliance officer about how the law applies to you.

Call (567) 202-2660 Get a Quote