What Is the Gramm-Leach-Bliley Act? A Plain-English Guide for Business Owners

The Gramm Leach Bliley act (GLBA) is a 1999 US federal law that requires financial institutions to explain how they share and protect their customers’ nonpublic personal information. Also known as the financial services modernization act of 1999, this legislation fundamentally changed how financial companies operate.
Its lasting impact on everyday business owners is simpler than the banking-industry history: the law created strict data security and privacy mandates that now affect non-bank businesses across every sector.
If you are asking what is the gramm-leach-bliley act in practical terms, you need to look at how the government enforces it today. For non-bank businesses, the FTC’s Safeguards Rule handles data security. It lives at 16 CFR Part 314. Meanwhile, the Privacy Rule governs privacy notices. Together, these regulations force companies to lock down sensitive customer data and be completely transparent about how that data is used.
The bottom line for Chicagoland business owners: If your company handles consumer financial data, the GLBA is a strict legal requirement. You are responsible for building a written information security program to protect it.
The Three Main Rules of GLBA
Here is how the three main rules break down at a glance, with the full detail below:
| Rule | What it Requires | Who it Protects |
|---|---|---|
| Financial Privacy Rule | Clear privacy notices disclosing what nonpublic personal information (NPI) you collect, who you share it with, how you protect it, and the consumer’s right to opt out of certain sharing | Consumers whose NPI you collect |
| Safeguards Rule | A written information security program with technical controls, risk assessments, and continuous monitoring, enforced under 16 CFR Part 314 | Customer information held in your systems |
| Pretexting Protections | Protection against pretexting (social engineering used to obtain financial data). A related FTC rule under the Fair and Accurate Credit Transactions Act (FACTA), the Disposal Rule (16 CFR Part 682), separately requires secure destruction of consumer report information and commonly applies alongside GLBA for financial institutions | Consumers’ data, from fraudulent access under false pretenses |
Each rule is explained in more detail below.
The GLBA Financial Privacy Rule
Under Gramm Leach Bliley Act title V, businesses must provide clear privacy notices to their customers.
The GLBA financial privacy rule dictates that you must explain exactly what nonpublic personal information NPI you collect. You also have to disclose where that information goes, who you share it with, and how you protect it. Most importantly, this rule gives consumers the right to opt out of having their information shared with certain third parties.
The GLBA Safeguards Rule
The GLBA safeguards rule is the heavy IT security requirement. The FTC Safeguards Rule (16 CFR Part 314) requires non-bank “financial institutions” under FTC jurisdiction to develop, implement, and maintain a written information security program to protect customer information. This is not a vague suggestion to use strong passwords. It is a strict, prescriptive checklist of technical controls, risk assessments, and continuous monitoring that your business must actively manage.
Pretexting Protections
The law also includes provisions to stop “pretexting,” which is a form of social engineering where someone lies to obtain private financial data. Under GLBA, businesses must take steps to verify the identity of anyone requesting customer information before disclosing it. This means training employees to recognize social-engineering tactics and implementing verification procedures for data requests.
The GLBA Disposal Rule
The GLBA disposal rule requires the secure destruction of consumer data when you no longer need it. You cannot throw old loan applications in a standard recycling bin or leave old hard drives sitting in a storage closet. Financial institution data privacy requires verified, permanent data destruction.
For businesses handling physical records or retired hardware, this means a documented chain of custody from collection through certified destruction, shredding for paper, degaussing or physical destruction for drives, and a certificate of destruction for your compliance file.
Who Does GLBA Apply To? The Surprise List
When business owners ask who does GLBA apply to, they usually assume the answer is just traditional banks and credit unions. That assumption is dangerous. The Rule covers non-bank “financial institutions” as the FTC defines them, which surprises many owners.
If your business is significantly engaged in providing financial products or services to consumers, assume you are covered until proven otherwise.
You can read more about who must comply with the Safeguards Rule to see the exact definitions. The FTC specifically lists the following types of businesses:
- Auto dealers that arrange financing or leasing
- Mortgage brokers and non-bank lenders
- Payday and consumer lenders
- Finance companies
- Tax preparation firms
- Accountants and CPA firms
- Debt collectors
- Check cashers
- Wire transferors
- Investment advisers not required to register with the SEC
- Real estate settlement services
- Colleges and universities participating in federal student aid (for that aid data)
What GLBA Compliance Means Day-to-Day for Your Business
Federal trade commission financial privacy regulations are not static. Here is how the law and its enforcement have evolved since 1999:
| Date | What Changed |
|---|---|
| 1999 | GLBA enacted, also known as the Financial Services Modernization Act of 1999 |
| 2021 | The FTC amends the Safeguards Rule to add prescriptive technical requirements |
| June 9, 2023 | The amended Rule’s key prescriptive provisions become mandatory |
| May 13, 2024 | A 30-day breach-notification requirement takes effect for security events involving the unencrypted information of 500 or more consumers |
To meet these requirements, Section 314.4 requires nine specific elements that must be part of your daily operations. You can find the FTC Safeguards Rule explained in detail across our resources, but here is the core checklist:

- Designate a Qualified Individual: You must name a single person responsible for implementing and supervising the information security program. It can be an employee or a person at an affiliate or service provider (many covered SMBs designate a role supported by their MSP), but the business retains legal responsibility for compliance.
- Conduct a Written Risk Assessment: You must base your security program on a formal, written evaluation of your risks.
- Implement Technical Safeguards: This includes access controls, a data inventory, change management, and monitoring or logging of authorized user activity. The amended Rule specifically requires encryption of customer information both at rest and in transit. It also mandates multi-factor authentication (MFA) for any individual accessing any information system that holds customer information, unless the Qualified Individual approves in writing a reasonably equivalent control.
- Regularly Test the Safeguards: You must perform continuous monitoring or conduct annual penetration testing plus vulnerability assessments at least every six months.
- Train Your Staff: You must provide regular security awareness training to your employees.
- Oversee Service Providers: You must manage your vendors by contract and periodic assessment to ensure they also protect your data.
- Keep the Program Current: You must update your security measures as your business changes or as new threats emerge.
- Maintain an Incident Response Plan: You must have a written plan detailing exactly what you will do if a breach occurs.
- Report to Leadership: The Qualified Individual must report in writing to the board or senior leadership at least annually.
The core deliverable that ties all of this together is the written information security program (WISP). The WISP is a written document describing how the business protects customer information. It is built on the written risk assessment and covers the required safeguards, testing, training, vendor oversight, and incident response.
The Cost of Ignoring the Rules
Unlike PCI DSS, which is maintained by the payments industry rather than a federal regulator, the Safeguards Rule is enforced directly by the federal government. The FTC can investigate, bring enforcement actions, impose consent orders with ongoing compliance obligations, and seek civil penalties for continued violations. A consent order effectively puts your IT environment under federal supervision. That is an expensive and stressful process for any business owner, it means ongoing audits, mandated reporting, and federal oversight of your security program.
See Where You Stand
Free 2-minute Safeguards Rule self-check: 8 plain-English questions, your risk level and the gaps to fix. No sign-up to see your result. free 2-minute Safeguards Rule risk check
Related Guides
- GLBA Compliance: Who it Covers and What it Requires
- What Is the FTC Safeguards Rule? Who it Covers, What Changed
- Who Must Comply With the FTC Safeguards Rule? The Full List
- How to Write a WISP for the FTC Safeguards Rule
- GLBA / FTC Safeguards Rule Requirements: The 9 Elements
- FTC Safeguards Rule for Auto Dealers: What Dealerships Must Do
- FTC Safeguards Rule for Tax Preparers and CPA Firms
Frequently Asked Questions
What is the main purpose of the Gramm-Leach-Bliley Act?
The primary purpose is to protect consumer financial information from unauthorized access and misuse. It requires businesses to explain their information-sharing practices to customers and to actively secure sensitive data through robust it controls. This ensures that personal details remain confidential and safe from cyber threats.
What are the three key rules of GLBA?
The law is built on three main pillars known as the Financial Privacy Rule, the Safeguards Rule, and the Disposal Rule. The Privacy Rule governs how you disclose data collection practices to consumers. The Safeguards Rule dictates the technical IT security program you must build, and the Disposal Rule covers how you securely destroy data when it is no longer needed.
Who needs to comply with GLBA?
Compliance is required for any business that is significantly engaged in providing financial products or services to consumers. This includes traditional banks but also extends to auto dealers, mortgage brokers, tax preparers, CPA firms, debt collectors, and even colleges that handle federal student aid data. If you handle consumer financial data, you should assume the rules apply to your operations.
What are examples of GLBA violations?
Violations occur when a business fails to implement the required security controls or privacy notices. Common examples include failing to use multi-factor authentication, storing consumer data without encryption, or neglecting to write a formal incident response plan. Failing to report a breach of 500 or more consumers to the FTC within 30 days is also a major violation.
Is GLBA still relevant today?
Yes, it is more relevant than ever due to recent regulatory updates. The FTC amended the Safeguards Rule in 2021 to include strict, highly prescriptive it requirements that became mandatory in 2023. Federal enforcement is active, and businesses must continuously update their security programs to stay compliant.
Get Help With FTC Safeguards Rule Compliance
LeadingIT is a Chicagoland managed it and cybersecurity provider that helps you become and stay compliant with federal regulations. We have helped Illinois businesses since 2010 and serve roughly 200 organizations and 2,500+ users from our offices in Woodstock and Manteno. LeadingIT implements and operates the technical safeguards the Rule requires (including MFA, encryption, monitoring, testing, and incident response) and can serve as or support the Qualified Individual role.
If you are ready to secure your business, explore LeadingIT’s FTC Safeguards compliance services. You can also contact us directly or book a call to schedule a consultation. Call us today at 815-788-6041.
