What Is GLBA? The Safeguards Rule Explained

GLBA (Gramm-Leach-Bliley Act): The Privacy Law Behind Financial Services IT

If your business provides financial products or services to consumers (loans, insurance, investment advice, tax preparation, mortgage brokering), GLBA is the federal law that governs how you protect and share their personal financial information.

GLBA was signed in 1999 and spent years in the shadow of better-known rules like HIPAA and PCI DSS. That changed when the FTC amended its Safeguards Rule in 2021, with most of the new requirements taking effect in June 2023, and then added a breach notification requirement in May 2024. If your firm hasn't revisited its GLBA program since those changes, it is probably out of date.

What does GLBA stand for?

Gramm-Leach-Bliley Act. It is named for its sponsors: Senator Phil Gramm, Representative Jim Leach and Representative Thomas Bliley. The law did two big things. It removed Depression-era barriers between banking, insurance and investment firms, and it created privacy and security requirements for how financial institutions handle consumer data. The IT and compliance world cares about the second part.

The simple way to think about it

GLBA is the financial services counterpart to HIPAA. Where HIPAA protects health information, GLBA protects nonpublic personal information (NPI): the financial details a consumer shares when seeking or using financial services. Think account numbers, Social Security numbers, income, credit history, investment holdings and tax return data.

Who has to comply?

GLBA applies to "financial institutions," and the definition is broader than most people expect. It covers:

  • Banks, credit unions and savings associations
  • Insurance companies and agencies
  • Investment advisers and broker-dealers
  • Mortgage lenders and brokers
  • Tax preparation services
  • Auto dealers that arrange financing
  • Payday lenders and check cashers
  • Accountants and other firms offering financial planning
  • Real estate settlement services

Which agency's rule applies depends on what kind of institution you are, and this matters more than people think:

  • Non-bank financial businesses such as tax preparers, mortgage brokers, auto dealers, and some accountants and financial planners that are not registered with the SEC fall under the FTC Safeguards Rule.
  • SEC-registered investment advisers and broker-dealers meet their GLBA obligations through the SEC's Regulation S-P, not the FTC rule. Our SEC/FINRA entry covers Reg S-P and its 2024 amendments.
  • Banks and credit unions follow the safeguards guidelines of their federal banking regulators.
  • Insurance is largely handled by state insurance regulators.

Plenty of small financial firms operate for years without realizing they are covered.

The three parts of GLBA that matter

The Privacy Rule requires financial institutions to tell customers what personal information they collect, how they use it and with whom they share it, and in some cases to let customers opt out of sharing with third parties. It is the privacy notice you've seen from your bank.

The Safeguards Rule requires a written information security program to protect customer information. This is the IT-heavy part.

The pretexting provisions prohibit obtaining customer information under false pretenses, such as someone impersonating a customer on the phone. For you, this is mostly a staff training and verification-procedure issue.

What the FTC Safeguards Rule requires

For businesses under the FTC's rule, the amended Safeguards Rule requires you to:

  • Designate a qualified individual to oversee the information security program
  • Base the program on a written risk assessment
  • Limit access to customer information to the people who need it
  • Encrypt customer information in transit and at rest
  • Use multi-factor authentication (MFA) for anyone accessing information systems
  • Monitor and log the activity of authorized users
  • Test or monitor your safeguards regularly
  • Train staff on security
  • Keep a written incident response plan
  • Oversee service providers that can access customer information
  • Have the qualified individual report to the board or a senior officer at least annually

Firms that maintain information on fewer than 5,000 consumers are exempt from a few of the documentation-heavy items, such as the written incident response plan and the annual report. The core security controls still apply. For a practical walkthrough, see our guide to building a WISP under the FTC Safeguards Rule.

The FTC breach notification requirement

Since May 13, 2024, a business covered by the FTC rule must notify the FTC within 30 days of discovering a security event involving unencrypted information of 500 or more consumers. That makes encryption and good logging more than best practice: they can decide whether a reportable event happened at all. Florida's own breach law, the Florida Information Protection Act (FIPA), can apply to the same incident.

The "we're too small for GLBA" myth

A common belief in small financial firms is that GLBA is for big banks, not a three-person mortgage brokerage or an independent tax preparer. Coverage depends on what you do, not how big you are. The small-firm exemptions are narrow and mostly trim paperwork; they don't remove the underlying security obligations.

What happens when GLBA is violated?

Enforcement is split by regulator: the FTC for non-bank financial businesses, the SEC for registered advisers and broker-dealers, federal banking agencies for banks and credit unions, and state regulators in some areas. Consequences can include consent orders that impose years of oversight, civil penalties, and in cases of intentional pretexting, criminal charges. State attorneys general can also act under state breach and consumer protection laws. The FTC has brought Safeguards Rule cases against mortgage companies, auto dealers and financial technology firms.

How GLBA connects to managed IT services

The Safeguards Rule reads a lot like the checklist a good Managed Service Provider (MSP) should already be working from. For financial clients, that means:

  • MFA on every system that touches customer information, including Microsoft 365 email
  • Encryption of customer information at rest and in transit, including email and file transfers
  • Access controls and least-privilege permissions
  • Audit logging of who accessed what and when
  • Patch management and monitoring through RMM
  • Endpoint protection, including EDR on every device that touches customer data
  • Security awareness training for staff
  • Incident response planning that is written down and practiced
  • Vendor oversight for every service that touches customer information

That last point deserves attention. Under GLBA you are responsible for overseeing your service providers, which includes your IT provider, cloud storage, email platform and CRM.

How GLBA fits with other frameworks

  • SEC rules (Regulation S-P, Reg S-ID and books-and-records rules) apply to registered advisers and broker-dealers. FINRA rules apply to broker-dealers.
  • SOX applies to public companies and their auditors, not to private advisory firms.
  • NIST frameworks, especially the Cybersecurity Framework, are commonly used as a practical guide for building a Safeguards program.
  • State laws such as Florida's FIPA (data security and breach notification) can add obligations on top of the federal baseline.
  • PCI DSS applies separately if you take card payments.

The same core controls (MFA, encryption, access control, logging, endpoint protection) support most of these frameworks. A well-built security program doesn't need rebuilding for each one; it needs to be documented and mapped. NerdSquad helps financial firms put those controls and records in place. See how we support financial advisers and wealth managers.

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT for financial advisers and wealth managers