If your business provides financial products or services to consumers (loans, insurance, investment advice, tax preparation, mortgage brokering), GLBA is the federal law that governs how you protect and share their personal financial information.
GLBA was signed in 1999 and spent years in the shadow of better-known rules like HIPAA and PCI DSS. That changed when the FTC amended its Safeguards Rule in 2021, with most of the new requirements taking effect in June 2023, and then added a breach notification requirement in May 2024. If your firm hasn't revisited its GLBA program since those changes, it is probably out of date.
Gramm-Leach-Bliley Act. It is named for its sponsors: Senator Phil Gramm, Representative Jim Leach and Representative Thomas Bliley. The law did two big things. It removed Depression-era barriers between banking, insurance and investment firms, and it created privacy and security requirements for how financial institutions handle consumer data. The IT and compliance world cares about the second part.
GLBA is the financial services counterpart to HIPAA. Where HIPAA protects health information, GLBA protects nonpublic personal information (NPI): the financial details a consumer shares when seeking or using financial services. Think account numbers, Social Security numbers, income, credit history, investment holdings and tax return data.
GLBA applies to "financial institutions," and the definition is broader than most people expect. It covers:
Which agency's rule applies depends on what kind of institution you are, and this matters more than people think:
Plenty of small financial firms operate for years without realizing they are covered.
The Privacy Rule requires financial institutions to tell customers what personal information they collect, how they use it and with whom they share it, and in some cases to let customers opt out of sharing with third parties. It is the privacy notice you've seen from your bank.
The Safeguards Rule requires a written information security program to protect customer information. This is the IT-heavy part.
The pretexting provisions prohibit obtaining customer information under false pretenses, such as someone impersonating a customer on the phone. For you, this is mostly a staff training and verification-procedure issue.
For businesses under the FTC's rule, the amended Safeguards Rule requires you to:
Firms that maintain information on fewer than 5,000 consumers are exempt from a few of the documentation-heavy items, such as the written incident response plan and the annual report. The core security controls still apply. For a practical walkthrough, see our guide to building a WISP under the FTC Safeguards Rule.
Since May 13, 2024, a business covered by the FTC rule must notify the FTC within 30 days of discovering a security event involving unencrypted information of 500 or more consumers. That makes encryption and good logging more than best practice: they can decide whether a reportable event happened at all. Florida's own breach law, the Florida Information Protection Act (FIPA), can apply to the same incident.
A common belief in small financial firms is that GLBA is for big banks, not a three-person mortgage brokerage or an independent tax preparer. Coverage depends on what you do, not how big you are. The small-firm exemptions are narrow and mostly trim paperwork; they don't remove the underlying security obligations.
Enforcement is split by regulator: the FTC for non-bank financial businesses, the SEC for registered advisers and broker-dealers, federal banking agencies for banks and credit unions, and state regulators in some areas. Consequences can include consent orders that impose years of oversight, civil penalties, and in cases of intentional pretexting, criminal charges. State attorneys general can also act under state breach and consumer protection laws. The FTC has brought Safeguards Rule cases against mortgage companies, auto dealers and financial technology firms.
The Safeguards Rule reads a lot like the checklist a good Managed Service Provider (MSP) should already be working from. For financial clients, that means:
That last point deserves attention. Under GLBA you are responsible for overseeing your service providers, which includes your IT provider, cloud storage, email platform and CRM.
The same core controls (MFA, encryption, access control, logging, endpoint protection) support most of these frameworks. A well-built security program doesn't need rebuilding for each one; it needs to be documented and mapped. NerdSquad helps financial firms put those controls and records in place. See how we support financial advisers and wealth managers.
NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.