Financial institutions answer to several privacy regulators at once, and the exemptions that once kept them outside state privacy laws are narrowing. This hub covers that convergence.

GLBA

The CFPB's Personal Financial Data Rights Rule: The Text of Part 1033 and the Injunction That Froze It

September 14, 2026

The Personal Financial Data Rights Rule, 12 CFR part 1033, requires banks, card issuers and other data providers to make consumer financial data available to consumers and authorized third parties. The rule remains on the books, but since October 29, 2025 the CFPB has been enjoined from enforcing it while it reconsiders the rule, and appeals from that order are paused.

Read more →
Data Security Rules

The NAIC Insurance Data Security Model Law: What Model #668 Requires and How Eight States Rewrote It

September 14, 2026

The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.

Read more →
GLBA

The GLBA Safeguards Rule: What 16 CFR Part 314 Requires, and of Whom

August 24, 2026

The Gramm-Leach-Bliley Act splits its privacy and security duties across several regulators, and the FTC's share lands on non-bank businesses that rarely call themselves financial institutions. This guide works through 16 CFR Part 314 as written: the coverage test, the nine enumerated elements, the exemption for smaller holders and the reporting duty that took effect in 2024.

Read more →
Ransomware

Ransomware Notification: The Federal and Sectoral Obligations an Extortion Incident Triggers

August 24, 2026

A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.

Read more →