Financial Services

Financial Services Privacy Law

The financial services industry handles some of the most sensitive personal information, from bank account numbers to investment portfolios, credit histories to transaction records. With stringent federal regulations, evolving state privacy laws, and the rapid digitization of financial services, banks, credit unions, investment firms, and FinTech companies face a complex web of privacy compliance requirements.

What GLBA Regulates

The Gramm-Leach-Bliley Act governs how financial institutions handle nonpublic personal information, and its reach turns on a definition that is far broader than the word bank suggests. A financial institution is any business significantly engaged in financial activities, which brings in mortgage brokers, auto dealers that extend or arrange credit, payday lenders, tax preparation firms, debt collectors, investment advisers and a large share of the FinTech sector alongside the depository institutions.

Nonpublic personal information means personally identifiable financial information that is not publicly available: what a customer puts on an application, including income, Social Security number and assets; account balances, payment history and transaction records; information obtained from third parties such as credit reports and employment verification; and the mere fact that someone is a customer of the institution. That last item catches people out, because it means the customer relationship itself is protected information.

The statute is implemented through three distinct obligations. The Privacy Rule requires notice of information-sharing practices and, in defined circumstances, an opportunity to opt out. The Safeguards Rule requires a security program to protect the information. The pretexting provisions prohibit obtaining customer information under false pretences. They are enforced by different agencies depending on the institution: the FTC for most non-bank businesses, the CFPB through Regulation P at 12 CFR Part 1016, and the federal banking regulators for the institutions they supervise.

Notices and the Limits of Opt-Out

An institution must provide an initial privacy notice at the start of the customer relationship, describing what it collects, with whom it shares, and how it protects the information. It must provide a revised notice before sharing in a way the existing notice did not describe. It must provide an annual notice, subject to an exception added by the FAST Act: an institution that has not changed its practices and shares only in ways that do not trigger an opt-out right may omit the annual delivery.

The opt-out right is narrower than the notice requirement implies. It attaches to sharing with nonaffiliated third parties, and it is subject to exceptions broad enough to cover most ordinary operations: sharing with service providers performing functions for the institution, sharing to process a transaction the customer requested, sharing with consent, and sharing for fraud prevention or legal compliance. Sharing among affiliates is largely outside GLBA and governed instead by the FCRA affiliate marketing rules, which give a separate opt-out for marketing use of shared eligibility information.

The Safeguards Rule After the 2021 Amendments

The Safeguards Rule was for two decades a process standard: institutions were required to have a written program appropriate to their size and complexity, with little specification of content. The amended rule is prescriptive, and the difference is substantive rather than editorial.

It now requires a designated qualified individual responsible for the program, a written risk assessment with defined criteria rather than an informal review, access controls limited to what each user needs, an inventory of where customer information is collected and stored, encryption of customer information in transit and at rest, multi-factor authentication for anyone accessing an information system, secure development practices for in-house applications, disposal of customer information generally within two years of the last use, change management procedures, monitoring of authorised user activity, continuous monitoring or periodic penetration testing and vulnerability assessments, written oversight of service providers, a written incident response plan, and an annual written report from the qualified individual to the board or governing body. Institutions maintaining information on fewer than 5,000 consumers are exempt from several of these specific requirements but not from the underlying obligation.

Fair Credit Reporting

The FCRA regulates consumer reports rather than financial institutions as such, and it binds three separate parties. Consumer reporting agencies must follow reasonable procedures to assure maximum possible accuracy and must investigate disputes. Furnishers, meaning the institutions that report account data, must not report information they know or have reasonable cause to believe is inaccurate, and must investigate disputes routed to them. Users must have a permissible purpose before obtaining a report, and must give adverse action notice when they act on one.

The permissible purposes are enumerated, and credit, insurance underwriting, employment, tenancy and account review are among them. Obtaining a report without one is a violation independent of what is done with it. FACTA amendments added identity theft protections layered on top: the disposal rule, fraud alerts and credit freezes, the red flags rules requiring an identity theft prevention program, and truncation of card numbers on receipts.

Payment Data and the PCI Question

Payment card data occupies an unusual position. The Payment Card Industry Data Security Standard is not law. It is a contractual standard imposed by the card brands through acquiring banks, and it is enforced through those contracts by way of fines, increased transaction fees and, at the extreme, loss of the ability to accept cards. A business can be fully compliant with GLBA and in breach of PCI DSS, or the reverse.

The standard does acquire indirect legal force. Several state statutes reference it, an FTC action under Section 5 may cite a failure to meet widely accepted security practice, and in litigation following a card breach the standard tends to be treated as evidence of the applicable standard of care even though it carries no statutory authority of its own.

State Law and the Financial Institution Exemption

Most state comprehensive privacy statutes contain a GLBA exemption, but the exemptions differ in a way that matters. Some exempt the information covered by GLBA; others exempt the financial institution itself. Under an information-level exemption, data outside GLBA’s scope, such as website analytics, marketing lists or job applicant records, remains subject to the state statute. Under an entity-level exemption, the institution is out of scope entirely. California uses an information-level exemption, which is why financial institutions doing business there face CCPA obligations for a defined slice of their data despite being federally regulated.

State law adds obligations elsewhere too. New York’s Department of Financial Services cybersecurity regulation applies its own program, reporting and certification requirements to covered entities, on a timeline independent of federal rulemaking.

Frequently Asked Questions

Who has to comply with the Safeguards Rule?

Financial institutions under FTC jurisdiction, and the rule defines that term broadly. It covers mortgage brokers, auto dealers that extend or arrange credit, payday lenders, tax preparation firms, collection agencies and similar non-bank businesses, not only banks.

What does the Safeguards Rule actually require?

A written information security program with a qualified individual in charge, a written risk assessment, access controls, encryption of customer information in transit and at rest, multi-factor authentication, monitoring and testing, oversight of service providers, a written incident response plan, and an annual report to the board or governing body.

Can customers stop a bank sharing their information?

The GLBA Privacy Rule requires notice of sharing practices and, for sharing with nonaffiliated third parties outside the listed exceptions, an opportunity to opt out. Sharing with affiliates is handled separately, including under the FCRA affiliate marketing rules.

Are annual privacy notices still required?

Not always. An institution may skip the annual notice if it has not changed the policies described in its most recent notice and shares only in ways that do not trigger an opt-out right, under an exception added by the FAST Act.

When does the Fair Credit Reporting Act come into it?

Whenever a consumer report is obtained for a permissible purpose such as credit, insurance, employment or tenancy. FCRA imposes separate duties on the furnisher of the information, the consumer reporting agency and the user of the report, including adverse action notices.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.