Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

GLBA Compliance: Who It Covers, What It Requires, and How to Get Ready

July 13, 2026

Achieving GLBA compliance means meeting strict federal requirements to protect the consumer financial data your business handles. The Gramm-Leach-Bliley Act (GLBA) is a 1999 US federal law that requires financial institutions to explain how they share and protect their customers’ nonpublic personal information.

For non-bank businesses, the data security piece of this law is implemented by the FTC through the Safeguards Rule (16 CFR Part 314). The privacy notice piece is handled by the Privacy Rule.

Two obligations, one security program. Figuring out what is GLBA compliance for your specific operation comes down to understanding these two core obligations. You must tell your customers how you share their data, and you must prove you have the technical security controls in place to protect that data from unauthorized access.

If you need a refresher on what the GLBA is, start there. This guide picks up from there: who falls under FTC jurisdiction, what your GLBA information security program must include, and how to prepare your business for federal scrutiny.

Who Must Comply With the GLBA

The FTC defines “financial institutions” much more broadly than traditional banks. If your business is significantly engaged in providing financial products or services to consumers, assume you are covered until proven otherwise.

This broad definition surprises many business owners. Use the table below to see where your operation lands.

Business TypeCovered Under GLBA?
Auto dealersYes, when they arrange financing or leasing
Mortgage brokersYes
Non-bank lenders, including payday lenders, consumer lenders, and finance companiesYes
Tax preparation firms, accountants, and CPA firmsYes
Debt collectorsYes
Check cashers and wire transferorsYes
Investment advisersYes, if not required to register with the SEC
Real estate settlement servicesYes
Colleges and universitiesYes, when they participate in federal student aid

Many of these businesses do not consider themselves financial institutions. However, the FTC looks at the nature of the data you process. If you facilitate loans, offer financial advice, or process tax returns, you hold the exact type of nonpublic personal information the law is designed to protect. Colleges and universities are covered for the same reason: they handle student financial aid data.

Collection agencies face heightened GLBA scrutiny because they hold consumer financial data across multiple creditors, often aggregated on legacy systems. If your agency handles payment histories, account balances, or debtor personal identifiers, three Safeguards Rule elements are especially relevant.

  • The data inventory (element 2) forces you to map every system where debtor NPI lives.
  • Access controls (element 3) limit who inside your agency can reach it.
  • Vendor oversight (element 6) matters because every creditor whose data you process counts as a separate data owner whose information your security program must protect.

The Safeguards Rule Requirements Summarized

The FTC amended the Safeguards Rule in 2021. The key prescriptive provisions of this update became mandatory on June 9, 2023. Section 314.4 outlines nine specific elements you must implement. Together, these elements form your written information security program.

You can use the following nine elements as a GLBA compliance checklist to evaluate your current security posture. Work through it row by row. Any row you cannot back up with written evidence is a gap.

#RequirementWhat it Means
1Designate a Qualified IndividualOne person implements and supervises your information security program. They can be an employee or a person at an affiliate or service provider, but your business retains legal responsibility for compliance.
2Conduct a written risk assessmentA formal, written GLBA risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information. It is the foundation for the rest of your security decisions.
3Implement technical safeguardsA written information security program (WISP) covering access controls, encryption, multi-factor authentication, and the other controls detailed below.
4Regularly test your safeguardsEither continuous monitoring of your systems, or annual penetration testing combined with vulnerability assessments at least every six months.
5Train your staffGLBA employee security training that builds security awareness and covers the specific threats targeting consumer financial data. Human error remains a massive security risk.
6Oversee your service providersGLBA vendor management by contract and periodic assessment, ensuring providers maintain appropriate safeguards for the customer data you share with them. You cannot outsource your compliance responsibility.
7Keep the program currentEvaluate and adjust your security program as your business changes, as technology evolves, or as the results of your security testing dictate.
8Maintain an incident response planA written plan that clearly defines the internal processes your business will follow to respond to and recover from any security event materially affecting the confidentiality, integrity, or availability of customer information.
9Report to leadershipThe Qualified Individual reports in writing to your board of directors or senior leadership at least annually on the overall status of the program and compliance with the Safeguards Rule.

What the Technical Safeguards Must Include

Element 3 carries the most technical weight, so the Rule spells it out in detail. If you are unsure where to start, you can review how to build your WISP to meet these GLBA safeguards rule requirements. The amended Rule specifically dictates that your technical safeguards must include:

  • Strict access controls to limit who can view customer information.
  • A complete data inventory of where customer information is stored.
  • Strict GLBA encryption requirements for customer information both at rest and in transit.
  • Secure development practices for any applications you build.
  • Mandatory GLBA multi-factor authentication for any individual accessing any information system that holds customer information (unless the Qualified Individual approves in writing a reasonably equivalent control).
  • Secure disposal procedures for customer information you no longer need.
  • Change management procedures.
  • Continuous monitoring and logging of authorized user activity.

Taken together, these eight technical controls form a GLBA cybersecurity program. A cybersecurity program actively defends customer data through continuous monitoring, access management, and threat response. A compliance checklist documents what you did last quarter. Regulators and examiners look for the program.

One common blind spot involves office copiers, scanners, and multifunction printers (MFPs). If your staff can scan a tax return or loan application and email it directly from the device, that transmission carries nonpublic personal information and falls under the Rule’s encryption-in-transit requirement. Many CPAs and tax preparers use scan-to-email workflows daily without realizing the transmission must be encrypted end to end.

What a GLBA Audit Entails

The word “audit” does not appear in the Safeguards Rule itself, but in practice it is how regulated businesses experience GLBA enforcement. A GLBA audit is an external review of your entire information security program against the nine Section 314.4 elements. It goes well beyond the internal risk assessment (element 2) and periodic testing (element 4) that the Rule already requires you to perform yourself.

Unlike a penetration test or vulnerability scan, which probe your technical defenses, a GLBA audit examines your policies, procedures, and your Qualified Individual’s reporting structure. It reviews training records and vendor contracts.

An auditor or examiner will ask for written evidence that each of the nine elements is operational, not just documented. If your risk assessment says you encrypt customer data but your scan-to-email workflow sends it in the clear, that gap will surface.

Privacy Rule and Pretexting Rule Obligations

Beyond technical security controls, your business must also manage how it communicates with consumers and handles social engineering threats.

GLBA financial privacy rule compliance requires you to be transparent about your data practices. You must provide a GLBA annual privacy notice to your customers. This notice must explain what information you collect, who you share it with, and how you protect it. You must also give consumers the right to opt out if you plan to share their nonpublic personal information with certain unaffiliated third parties.

Additionally, the GLBA pretexting rule requires you to implement safeguards against social engineering. Pretexting occurs when someone tries to gain access to consumer financial information under false pretenses. For example, a criminal might call your front desk and pretend to be a customer to extract account details. Your security training and verification procedures must actively defend against these tactics.

Federal Enforcement and GLBA Compliance Penalties

Unlike PCI DSS, which is industry self-regulation with no government involvement, the Safeguards Rule is enforced directly by the federal government. The FTC has the authority to investigate your business, bring enforcement actions, and impose consent orders that typically carry 20 years of strict oversight obligations.

The FTC also seeks civil penalties for violations. GLBA non-compliance penalties are severe. The exact fines are inflation-adjusted and case-specific, but they can devastate a business.

Since May 13, 2024, covered businesses must report security events involving the unencrypted information of 500 or more consumers directly to the FTC within 30 days of discovery.

Enforcement has tightened steadily since the law first passed. The timeline below shows the key regulatory milestones:

DateWhat Changed
1999GLBA is enacted. Financial institutions must explain how they share and protect customers’ nonpublic personal information.
2021The FTC amends the Safeguards Rule (16 CFR Part 314).
June 9, 2023The key prescriptive provisions of the amended Rule become mandatory.
May 13, 2024The breach-notification requirement for security events involving 500 or more consumers takes effect.

Frequently Asked Questions

What are the three key rules of GLBA?

The Gramm-Leach-Bliley Act is built on three main components. The Financial Privacy Rule governs how you disclose data practices to consumers. The Safeguards Rule mandates the technical security program you must build to protect that data. The Pretexting Rule requires you to implement procedures to stop unauthorized people from accessing customer information under false pretenses.

Who needs to comply with GLBA?

The law covers financial institutions, but the FTC defines this term very broadly. It applies to non-bank businesses significantly engaged in providing financial products or services to consumers. This includes auto dealers, mortgage brokers, tax preparation firms, CPA firms, debt collectors, check cashers, and colleges participating in federal student aid.

What are the key requirements of GLBA compliance?

You must provide an annual privacy notice to consumers and build a comprehensive written information security program. Under the FTC Safeguards Rule, this program requires a designated Qualified Individual, a written risk assessment, multi-factor authentication, data encryption, regular vulnerability testing, employee security training, and strict vendor management.

What are the penalties for non-compliance with GLBA?

The FTC enforces the law directly and can impose severe civil penalties for non-compliance. While specific dollar amounts are inflation-adjusted and case-specific, violations can result in massive fines and federal consent orders. These consent orders typically force a business to undergo strict government oversight for many years.

How can financial institutions ensure GLBA compliance?

Businesses must start by conducting a formal risk assessment to identify their security gaps. From there, they must implement the nine specific elements required by Section 314.4 of the FTC Safeguards Rule. Because these requirements are highly technical, many businesses partner with a managed IT provider to implement the necessary encryption, multi-factor authentication, and continuous monitoring controls.

Get Help Meeting Your Compliance Requirements

Translating federal regulations into daily IT operations is difficult, but you do not have to do it alone. LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses protect their data since 2010. We serve roughly 200 organizations and 2,500+ users from our offices in Woodstock and Manteno.

While LeadingIT does not certify FTC compliance, as no such certification exists, we help you become and stay compliant. We implement and operate the exact technical safeguards the Rule requires. We manage your multi-factor authentication, data encryption, continuous monitoring, vulnerability testing, and incident response. We can also serve as or support your Qualified Individual role.

You can explore LeadingIT’s FTC Safeguards compliance services to see how we handle the heavy lifting. If you are ready to secure your business, take the free Risk-Check, book a call, or contact us directly at 815-788-6041.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.