GLBA Compliance: Who It Covers, What It Requires, and How to Get Ready

Achieving GLBA compliance means meeting strict federal requirements to protect the consumer financial data your business handles. The Gramm-Leach-Bliley Act (GLBA) is a 1999 US federal law that requires financial institutions to explain how they share and protect their customers’ nonpublic personal information.
For non-bank businesses, the data security piece of this law is implemented by the FTC through the Safeguards Rule (16 CFR Part 314). The privacy notice piece is handled by the Privacy Rule.
Two obligations, one security program. Figuring out what is GLBA compliance for your specific operation comes down to understanding these two core obligations. You must tell your customers how you share their data, and you must prove you have the technical security controls in place to protect that data from unauthorized access.
If you need a refresher on what the GLBA is, start there. This guide picks up from there: who falls under FTC jurisdiction, what your GLBA information security program must include, and how to prepare your business for federal scrutiny.
Who Must Comply With the GLBA
The FTC defines “financial institutions” much more broadly than traditional banks. If your business is significantly engaged in providing financial products or services to consumers, assume you are covered until proven otherwise.
This broad definition surprises many business owners. Use the table below to see where your operation lands.
| Business Type | Covered Under GLBA? |
|---|---|
| Auto dealers | Yes, when they arrange financing or leasing |
| Mortgage brokers | Yes |
| Non-bank lenders, including payday lenders, consumer lenders, and finance companies | Yes |
| Tax preparation firms, accountants, and CPA firms | Yes |
| Debt collectors | Yes |
| Check cashers and wire transferors | Yes |
| Investment advisers | Yes, if not required to register with the SEC |
| Real estate settlement services | Yes |
| Colleges and universities | Yes, when they participate in federal student aid |
Many of these businesses do not consider themselves financial institutions. However, the FTC looks at the nature of the data you process. If you facilitate loans, offer financial advice, or process tax returns, you hold the exact type of nonpublic personal information the law is designed to protect. Colleges and universities are covered for the same reason: they handle student financial aid data.
Collection agencies face heightened GLBA scrutiny because they hold consumer financial data across multiple creditors, often aggregated on legacy systems. If your agency handles payment histories, account balances, or debtor personal identifiers, three Safeguards Rule elements are especially relevant.
- The data inventory (element 2) forces you to map every system where debtor NPI lives.
- Access controls (element 3) limit who inside your agency can reach it.
- Vendor oversight (element 6) matters because every creditor whose data you process counts as a separate data owner whose information your security program must protect.
The Safeguards Rule Requirements Summarized
The FTC amended the Safeguards Rule in 2021. The key prescriptive provisions of this update became mandatory on June 9, 2023. Section 314.4 outlines nine specific elements you must implement. Together, these elements form your written information security program.
You can use the following nine elements as a GLBA compliance checklist to evaluate your current security posture. Work through it row by row. Any row you cannot back up with written evidence is a gap.
| # | Requirement | What it Means |
|---|---|---|
| 1 | Designate a Qualified Individual | One person implements and supervises your information security program. They can be an employee or a person at an affiliate or service provider, but your business retains legal responsibility for compliance. |
| 2 | Conduct a written risk assessment | A formal, written GLBA risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information. It is the foundation for the rest of your security decisions. |
| 3 | Implement technical safeguards | A written information security program (WISP) covering access controls, encryption, multi-factor authentication, and the other controls detailed below. |
| 4 | Regularly test your safeguards | Either continuous monitoring of your systems, or annual penetration testing combined with vulnerability assessments at least every six months. |
| 5 | Train your staff | GLBA employee security training that builds security awareness and covers the specific threats targeting consumer financial data. Human error remains a massive security risk. |
| 6 | Oversee your service providers | GLBA vendor management by contract and periodic assessment, ensuring providers maintain appropriate safeguards for the customer data you share with them. You cannot outsource your compliance responsibility. |
| 7 | Keep the program current | Evaluate and adjust your security program as your business changes, as technology evolves, or as the results of your security testing dictate. |
| 8 | Maintain an incident response plan | A written plan that clearly defines the internal processes your business will follow to respond to and recover from any security event materially affecting the confidentiality, integrity, or availability of customer information. |
| 9 | Report to leadership | The Qualified Individual reports in writing to your board of directors or senior leadership at least annually on the overall status of the program and compliance with the Safeguards Rule. |
What the Technical Safeguards Must Include
Element 3 carries the most technical weight, so the Rule spells it out in detail. If you are unsure where to start, you can review how to build your WISP to meet these GLBA safeguards rule requirements. The amended Rule specifically dictates that your technical safeguards must include:
- Strict access controls to limit who can view customer information.
- A complete data inventory of where customer information is stored.
- Strict GLBA encryption requirements for customer information both at rest and in transit.
- Secure development practices for any applications you build.
- Mandatory GLBA multi-factor authentication for any individual accessing any information system that holds customer information (unless the Qualified Individual approves in writing a reasonably equivalent control).
- Secure disposal procedures for customer information you no longer need.
- Change management procedures.
- Continuous monitoring and logging of authorized user activity.
Taken together, these eight technical controls form a GLBA cybersecurity program. A cybersecurity program actively defends customer data through continuous monitoring, access management, and threat response. A compliance checklist documents what you did last quarter. Regulators and examiners look for the program.
One common blind spot involves office copiers, scanners, and multifunction printers (MFPs). If your staff can scan a tax return or loan application and email it directly from the device, that transmission carries nonpublic personal information and falls under the Rule’s encryption-in-transit requirement. Many CPAs and tax preparers use scan-to-email workflows daily without realizing the transmission must be encrypted end to end.
What a GLBA Audit Entails
The word “audit” does not appear in the Safeguards Rule itself, but in practice it is how regulated businesses experience GLBA enforcement. A GLBA audit is an external review of your entire information security program against the nine Section 314.4 elements. It goes well beyond the internal risk assessment (element 2) and periodic testing (element 4) that the Rule already requires you to perform yourself.
Unlike a penetration test or vulnerability scan, which probe your technical defenses, a GLBA audit examines your policies, procedures, and your Qualified Individual’s reporting structure. It reviews training records and vendor contracts.
An auditor or examiner will ask for written evidence that each of the nine elements is operational, not just documented. If your risk assessment says you encrypt customer data but your scan-to-email workflow sends it in the clear, that gap will surface.
Privacy Rule and Pretexting Rule Obligations
Beyond technical security controls, your business must also manage how it communicates with consumers and handles social engineering threats.
GLBA financial privacy rule compliance requires you to be transparent about your data practices. You must provide a GLBA annual privacy notice to your customers. This notice must explain what information you collect, who you share it with, and how you protect it. You must also give consumers the right to opt out if you plan to share their nonpublic personal information with certain unaffiliated third parties.
Additionally, the GLBA pretexting rule requires you to implement safeguards against social engineering. Pretexting occurs when someone tries to gain access to consumer financial information under false pretenses. For example, a criminal might call your front desk and pretend to be a customer to extract account details. Your security training and verification procedures must actively defend against these tactics.
Federal Enforcement and GLBA Compliance Penalties
Unlike PCI DSS, which is industry self-regulation with no government involvement, the Safeguards Rule is enforced directly by the federal government. The FTC has the authority to investigate your business, bring enforcement actions, and impose consent orders that typically carry 20 years of strict oversight obligations.
The FTC also seeks civil penalties for violations. GLBA non-compliance penalties are severe. The exact fines are inflation-adjusted and case-specific, but they can devastate a business.
Since May 13, 2024, covered businesses must report security events involving the unencrypted information of 500 or more consumers directly to the FTC within 30 days of discovery.
Enforcement has tightened steadily since the law first passed. The timeline below shows the key regulatory milestones:

| Date | What Changed |
|---|---|
| 1999 | GLBA is enacted. Financial institutions must explain how they share and protect customers’ nonpublic personal information. |
| 2021 | The FTC amends the Safeguards Rule (16 CFR Part 314). |
| June 9, 2023 | The key prescriptive provisions of the amended Rule become mandatory. |
| May 13, 2024 | The breach-notification requirement for security events involving 500 or more consumers takes effect. |
Related Guides
- What Is the Gramm-Leach-Bliley Act (GLBA)? Plain English
- How to Write a WISP for the FTC Safeguards Rule
- What Is the FTC Safeguards Rule? Who it Covers, What Changed
- Who Must Comply With the FTC Safeguards Rule? The Full List
Frequently Asked Questions
What are the three key rules of GLBA?
The Gramm-Leach-Bliley Act is built on three main components. The Financial Privacy Rule governs how you disclose data practices to consumers. The Safeguards Rule mandates the technical security program you must build to protect that data. The Pretexting Rule requires you to implement procedures to stop unauthorized people from accessing customer information under false pretenses.
Who needs to comply with GLBA?
The law covers financial institutions, but the FTC defines this term very broadly. It applies to non-bank businesses significantly engaged in providing financial products or services to consumers. This includes auto dealers, mortgage brokers, tax preparation firms, CPA firms, debt collectors, check cashers, and colleges participating in federal student aid.
What are the key requirements of GLBA compliance?
You must provide an annual privacy notice to consumers and build a comprehensive written information security program. Under the FTC Safeguards Rule, this program requires a designated Qualified Individual, a written risk assessment, multi-factor authentication, data encryption, regular vulnerability testing, employee security training, and strict vendor management.
What are the penalties for non-compliance with GLBA?
The FTC enforces the law directly and can impose severe civil penalties for non-compliance. While specific dollar amounts are inflation-adjusted and case-specific, violations can result in massive fines and federal consent orders. These consent orders typically force a business to undergo strict government oversight for many years.
How can financial institutions ensure GLBA compliance?
Businesses must start by conducting a formal risk assessment to identify their security gaps. From there, they must implement the nine specific elements required by Section 314.4 of the FTC Safeguards Rule. Because these requirements are highly technical, many businesses partner with a managed IT provider to implement the necessary encryption, multi-factor authentication, and continuous monitoring controls.
Get Help Meeting Your Compliance Requirements
Translating federal regulations into daily IT operations is difficult, but you do not have to do it alone. LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses protect their data since 2010. We serve roughly 200 organizations and 2,500+ users from our offices in Woodstock and Manteno.
While LeadingIT does not certify FTC compliance, as no such certification exists, we help you become and stay compliant. We implement and operate the exact technical safeguards the Rule requires. We manage your multi-factor authentication, data encryption, continuous monitoring, vulnerability testing, and incident response. We can also serve as or support your Qualified Individual role.
You can explore LeadingIT’s FTC Safeguards compliance services to see how we handle the heavy lifting. If you are ready to secure your business, take the free Risk-Check, book a call, or contact us directly at 815-788-6041.
