Financial institutions answer to several privacy regulators at once, and the exemptions that once kept them outside state privacy laws are narrowing. This hub covers that convergence.
GLBA
September 14, 2026
The Personal Financial Data Rights Rule, 12 CFR part 1033, requires banks, card issuers and other data providers to make consumer financial data available to consumers and authorized third parties. The rule remains on the books, but since October 29, 2025 the CFPB has been enjoined from enforcing it while it reconsiders the rule, and appeals from that order are paused.
Read more →
Ransomware
September 14, 2026
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 wrote two reporting clocks into federal law but left their start date, and the definitions of who reports and what, to a CISA rulemaking that was due in October 2025. This sets out what the statute fixes, what the 2024 proposal would add, and where the rulemaking stood on September 14, 2026.
Read more →
Data Security Rules
September 14, 2026
The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.
Read more →
FCRA
September 7, 2026
The Fair Credit Reporting Act does not have one adverse action notice. It has a notice owed before a decision that only employers owe, and a notice owed after any adverse action taken on a consumer report by anyone. The two sit in different sections, carry different contents, and answer to different silences in the statute.
Read more →
FCRA
September 1, 2026
The Fair Credit Reporting Act does not ask credit bureaus to be careful about who receives a consumer's file. It gives a closed list of permissible purposes and forbids everything else, on both sides of the transaction — the agency that furnishes the report and the person who obtains it.
Read more →
GLBA
September 1, 2026
The FTC amended the Safeguards Rule in November 2023 to add a reporting duty at 16 CFR 314.4(j). It turns on acquisition of unencrypted customer information rather than on any assessment of harm, applies at 500 consumers, runs 30 days from discovery, and carries no small-institution exemption.
Read more →
Data Breaches
September 1, 2026
Item 1.05 of Form 8-K is an investor-disclosure obligation, not a breach-notification law: it is triggered by a registrant's determination that a cybersecurity incident is material, runs four business days from that determination, and asks about impact rather than incident detail.
Read more →
GLBA
September 1, 2026
Amendments adopted in May 2024 rewrote 17 CFR 248.30 to require broker-dealers, investment companies, registered advisers and transfer agents to maintain an incident response program and to notify affected individuals within 30 days. Both compliance dates have now passed.
Read more →
GLBA
August 24, 2026
The Gramm-Leach-Bliley Act splits its privacy and security duties across several regulators, and the FTC's share lands on non-bank businesses that rarely call themselves financial institutions. This guide works through 16 CFR Part 314 as written: the coverage test, the nine enumerated elements, the exemption for smaller holders and the reporting duty that took effect in 2024.
Read more →
Ransomware
August 24, 2026
A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.
Read more →