The Gramm-Leach-Bliley Act sets the privacy and data-security baseline for financial institutions, and the amended Safeguards Rule pulled a much wider set of businesses into scope than most expected. This hub tracks enforcement and the compliance obligations that follow.
GLBA
September 14, 2026
The Personal Financial Data Rights Rule, 12 CFR part 1033, requires banks, card issuers and other data providers to make consumer financial data available to consumers and authorized third parties. The rule remains on the books, but since October 29, 2025 the CFPB has been enjoined from enforcing it while it reconsiders the rule, and appeals from that order are paused.
Read more →
GLBA
September 1, 2026
The FTC amended the Safeguards Rule in November 2023 to add a reporting duty at 16 CFR 314.4(j). It turns on acquisition of unencrypted customer information rather than on any assessment of harm, applies at 500 consumers, runs 30 days from discovery, and carries no small-institution exemption.
Read more →
GLBA
September 1, 2026
Amendments adopted in May 2024 rewrote 17 CFR 248.30 to require broker-dealers, investment companies, registered advisers and transfer agents to maintain an incident response program and to notify affected individuals within 30 days. Both compliance dates have now passed.
Read more →
GLBA
August 24, 2026
The Gramm-Leach-Bliley Act splits its privacy and security duties across several regulators, and the FTC's share lands on non-bank businesses that rarely call themselves financial institutions. This guide works through 16 CFR Part 314 as written: the coverage test, the nine enumerated elements, the exemption for smaller holders and the reporting duty that took effect in 2024.
Read more →