Gramm-Leach-Bliley Act, Title V (Privacy Rule, Safeguards Rule, and pretexting provisions)
GLBA
Financial · Data security · Breach notification
GLBA requires financial institutions to give privacy notices, let consumers opt out of most sharing with nonaffiliated third parties, and protect customer information. The FTC's 2021 Safeguards Rule amendments require a detailed security program (qualified individual, encryption, MFA), and since May 13, 2024 require notice to the FTC of incidents involving 500 or more consumers. The SEC's 2024 Regulation S-P amendments require incident response programs and 30-day customer breach notice (compliance Dec. 3, 2025 for larger and June 3, 2026 for smaller entities).
- Where
- Federal
- Citation
- 15 U.S.C. 6801-6809, 6821-6827; 12 CFR Part 1016 (Regulation P); 16 CFR Part 314 (FTC Safeguards Rule); 17 CFR Part 248 (SEC Regulation S-P)
- Status
- In force
- In force since
- 2001-07-01
- Last amended
- 2024-08-02
- Enforced by
- CFPB, federal banking agencies, SEC, CFTC, NCUA, FTC (non-bank financial institutions), and state insurance regulators, by sector (15 U.S.C. 6805)
- People can sue
- No
- Penalties
- Enforced under each regulator's own authority; FTC Safeguards and Privacy Rule violations can support civil penalties for order or rule violations. Pretexting is a federal crime (up to 5 years; enhanced for aggravated cases).
- Applies to
- Financial institutions: businesses significantly engaged in financial activities (banks, lenders, brokers, insurers, many non-bank financial companies)
- Nonaffiliated third parties receiving nonpublic personal information (reuse limits)
- Any person, for the pretexting prohibition
What a privacy notice must say
- Provide clear and conspicuous initial and annual privacy notices describing sharing practices (annual notice excepted if practices unchanged and sharing is limited).15 U.S.C. 6803(a), (f); 12 CFR 1016.4-1016.5
Rights it gives people
- Before sharing nonpublic personal information with nonaffiliated third parties, give consumers notice and a reasonable opportunity to opt out, subject to exceptions.15 U.S.C. 6802(a)-(b); 12 CFR 1016.10
Practices it requires
- Do not obtain or attempt to obtain customer information from a financial institution by false pretenses (pretexting).15 U.S.C. 6821(a)
- Do not share account numbers with nonaffiliated third parties for marketing.15 U.S.C. 6802(d); 12 CFR 1016.12
Security duties
- Maintain a written information security program under a Qualified Individual, with risk assessment, encryption in transit and at rest, and multi-factor authentication.15 U.S.C. 6801(b); 16 CFR 314.4(a)-(c)
Breach duties
- Notify the FTC within 30 days of discovering a notification event involving unencrypted information of at least 500 consumers.16 CFR 314.4(j) · Only if: Non-bank financial institutions under FTC jurisdiction
- SEC-regulated broker-dealers, funds, advisers and transfer agents must maintain an incident response program and notify affected individuals within 30 days when sensitive customer information is reasonably likely to have been accessed without authorization; service providers must notify within 72 hours.17 CFR 248.30 · Only if: SEC-registered covered institutions · From 2025-12-03
Sources
- Official text
- 15 U.S.C. 6801-6803 (OLRC)
- 15 U.S.C. 6821 (OLRC)
- 12 CFR Part 1016 (eCFR)
- 16 CFR Part 314 (eCFR)
- 17 CFR Part 248 (eCFR)
- FTC, Standards for Safeguarding Customer Information, 88 FR (Nov. 13, 2023)
- SEC, Regulation S-P amendments (June 3, 2024)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Pretexting criminal penalty ranges (15 U.S.C. 6823) and 12 CFR 1016.12 were not read | effective_date uses the July 1, 2001 privacy compliance date stated in 17 CFR 248; GLBA was enacted Nov. 12, 1999
Research reference, not legal advice.