What it means
Before 1999, a set of laws from the 1930s, known together as Glass-Steagall, limited the extent to which one company could run a commercial bank, an investment bank and an insurance business. The reasoning was that mixing these activities had contributed to the banking failures of the Great Depression.
Over time, the rules were weakened by regulators and market practice, and the 1999 Act formally removed the main barriers. The Act created a new type of company called a financial holding company.
Within this structure, a bank holding company could own subsidiaries engaged in banking, securities underwriting and dealing, and insurance, subject to conditions on capital and management. This allowed the formation of large, diversified financial groups offering many services under one roof.
The law also included important consumer protections. The privacy rules require financial institutions to give customers a notice explaining what personal information they collect and share, and to let customers opt out of certain sharing with outside companies.
The safeguards rules require firms to have a written plan to protect customer data, and there are provisions against obtaining information through false pretences. For a business, the Act matters in two ways.
Companies that deal with banks or insurers benefit from the one-stop services that the law allowed, such as lending, advice and insurance from the same group. Companies that handle financial customers' data, such as processors or software providers, may face contract requirements arising from the safeguarding rules.
Enforcement is shared between several regulators, depending on the type of firm, and the privacy and safeguarding rules have been supplemented by later regulations. A compliance team should therefore treat the Act as a foundation and check which rules apply to its own business and to the type of customer data it holds.
The nuance is that the law is still debated. Supporters say it let firms compete and diversify, while critics argue that it made large institutions more complex and contributed to risks seen in later crises.
Other countries have their own Financial Services Acts, so the name alone does not identify the law.
In practice
Real-world examples.
Example
A large bank forms a financial holding company and buys an insurance broker. Customers can now arrange a mortgage, home insurance and a savings plan through one group. The bank reports the insurance fees as a separate line of income.
Example
A credit card processor serves several banks and must handle cardholder data under the safeguarding rules written into its contracts. Its compliance team keeps a written security plan and trains staff each year. A bank client audits the plan before renewing the contract, and the processor's finance team budgets $60,000 a year for the security controls and the audit work.
Example
A customer receives a privacy notice from her bank explaining that it shares some information with affiliates and, with her permission, with outside firms. She uses the opt-out form to restrict marketing from third parties. The bank records her choice in its systems and applies it to all of the group's affiliated companies, so she stops receiving the marketing offers within a few weeks.
Case study
Seen in the real world.
Crestmont Financial Group is an illustrative, fictional company that began as a regional bank. After the law changed, it set up a financial holding company and added an investment advisory arm and an insurance agency.
The finance director found that cross-selling was the main benefit. Of its 100,000 bank customers, 8% bought at least one new product, giving 100,000 x 0.08 = 8,000 new relationships. At an average fee income of $300 a year, that added 8,000 x 300 = $2,400,000 in annual revenue.
The group also had to build a compliance programme for privacy notices and data security, which cost about $400,000 in the first year for systems, training and legal review. The illustrative lesson is that wider permissions brought both new income and new obligations, so the finance director presented the net benefit to the board after deducting the extra compliance cost.
Watch out
Common mistakes.
- Assuming the Act only dealt with banking structure, when it also set privacy and data safeguarding rules for financial firms.
- Confusing it with the Financial Services Act passed in other countries, such as the United Kingdom, which are separate laws.
- Believing it repealed all of the Glass-Steagall restrictions, when it removed the main barriers between banks, securities firms and insurers.
Questions
People also ask.
What is another name for the Financial Services Act of 1999?
It is commonly called the Gramm-Leach-Bliley Act, after its main congressional sponsors, or the Financial Services Modernization Act.
What is a financial holding company?
It is a bank holding company that has qualified to own subsidiaries in banking, securities and insurance, subject to supervision.
Does the Act protect customer privacy?
Yes, it requires financial institutions to give privacy notices, offer opt-outs for some sharing and maintain safeguards for customer information.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
