Privacy Law Library

Gramm-Leach-Bliley Act, Title V (Privacy Rule, Safeguards Rule, and pretexting provisions)

GLBA

Financial · Data security · Breach notification

GLBA requires financial institutions to give privacy notices, let consumers opt out of most sharing with nonaffiliated third parties, and protect customer information. The FTC's 2021 Safeguards Rule amendments require a detailed security program (qualified individual, encryption, MFA), and since May 13, 2024 require notice to the FTC of incidents involving 500 or more consumers. The SEC's 2024 Regulation S-P amendments require incident response programs and 30-day customer breach notice (compliance Dec. 3, 2025 for larger and June 3, 2026 for smaller entities).

Where
Federal
Citation
15 U.S.C. 6801-6809, 6821-6827; 12 CFR Part 1016 (Regulation P); 16 CFR Part 314 (FTC Safeguards Rule); 17 CFR Part 248 (SEC Regulation S-P)
Status
In force
In force since
2001-07-01
Last amended
2024-08-02
Enforced by
CFPB, federal banking agencies, SEC, CFTC, NCUA, FTC (non-bank financial institutions), and state insurance regulators, by sector (15 U.S.C. 6805)
People can sue
No
Penalties
Enforced under each regulator's own authority; FTC Safeguards and Privacy Rule violations can support civil penalties for order or rule violations. Pretexting is a federal crime (up to 5 years; enhanced for aggravated cases).
Applies to
  • Financial institutions: businesses significantly engaged in financial activities (banks, lenders, brokers, insurers, many non-bank financial companies)
  • Nonaffiliated third parties receiving nonpublic personal information (reuse limits)
  • Any person, for the pretexting prohibition

What a privacy notice must say

  • Provide clear and conspicuous initial and annual privacy notices describing sharing practices (annual notice excepted if practices unchanged and sharing is limited).15 U.S.C. 6803(a), (f); 12 CFR 1016.4-1016.5

Rights it gives people

  • Before sharing nonpublic personal information with nonaffiliated third parties, give consumers notice and a reasonable opportunity to opt out, subject to exceptions.15 U.S.C. 6802(a)-(b); 12 CFR 1016.10

Practices it requires

  • Do not obtain or attempt to obtain customer information from a financial institution by false pretenses (pretexting).15 U.S.C. 6821(a)
  • Do not share account numbers with nonaffiliated third parties for marketing.15 U.S.C. 6802(d); 12 CFR 1016.12

Security duties

  • Maintain a written information security program under a Qualified Individual, with risk assessment, encryption in transit and at rest, and multi-factor authentication.15 U.S.C. 6801(b); 16 CFR 314.4(a)-(c)

Breach duties

  • Notify the FTC within 30 days of discovering a notification event involving unencrypted information of at least 500 consumers.16 CFR 314.4(j) · Only if: Non-bank financial institutions under FTC jurisdiction
  • SEC-regulated broker-dealers, funds, advisers and transfer agents must maintain an incident response program and notify affected individuals within 30 days when sensitive customer information is reasonably likely to have been accessed without authorization; service providers must notify within 72 hours.17 CFR 248.30 · Only if: SEC-registered covered institutions · From 2025-12-03

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Pretexting criminal penalty ranges (15 U.S.C. 6823) and 12 CFR 1016.12 were not read | effective_date uses the July 1, 2001 privacy compliance date stated in 17 CFR 248; GLBA was enacted Nov. 12, 1999

Research reference, not legal advice.