Back to Glossary

Entry · Banking

Gramm-Leach-Bliley Act (GLBA)

The Gramm-Leach-Bliley Act, or GLBA, is a US law enacted in 1999 that changed restrictions on financial-service activities and established protections concerning consumers' financial information. For organisations handling covered financial data, its privacy and security requirements can affect disclosures, information sharing and safeguards.

The law's application depends on the organisation, activity, regulator and relevant rules, not simply whether a business describes itself as a bank.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

The legislation is associated with changes that allowed broader combinations of banking, securities and insurance activities. That historical role is distinct from the consumer-data obligations commonly encountered by operating teams, so a glossary description should not reduce the entire law to either topic alone.

The FTC explains that covered financial institutions must tell customers about information-sharing practices and safeguard sensitive data. Businesses should determine which regulator and rules apply to them, because some non-bank activities can fall within the relevant definition of a financial institution.

Privacy notices describe how information is collected, shared and protected under the applicable requirements, and they are not merely a website decoration. Actual practices should match what the organisation tells its customers.

Certain sharing with non-affiliated third parties can require notice and an opportunity to opt out, subject to exceptions, so it is inaccurate to say that consumers can prevent every information transfer. The purpose, relationship and applicable exception matter.

The Safeguards Rule addresses security of customer information for institutions under the FTC's jurisdiction, and a privacy notice does not substitute for those controls. Security responsibilities concern how data is handled in practice, including access and service-provider arrangements.

A business should inventory the covered data it holds and the systems that use it, since customer financial information can appear in files, applications and outsourced processes and limiting attention to one central database can miss important exposures. Service providers can introduce risk even when the customer sees only the original company, and contracting out a task does not make responsibility disappear.

Review the applicable oversight duties and the provider's actual handling of information. Access should reflect work needs, so employees who do not need sensitive customer information should not receive it by default.

Strong security also depends on training, incident processes and practical monitoring, not only on written policies. Other privacy and security laws may apply at the same time, and GLBA should not be treated as a universal replacement for state requirements or every other federal rule.

Compliance analysis needs the specific business activities and data flows. For managers, start by asking whether the organisation and activity are covered, who supervises them and which obligations apply, then compare policy with actual operations and seek legal and security advice where the classification or implementation is uncertain.

In practice

Real-world examples.

1

Example

A financial-services business updates its customer privacy notice after changing how it shares data with a service provider. It also checks whether the actual sharing and any applicable exception match the notice. The compliance lead keeps the checked version and the date of the review.

2

Example

A company assumes GLBA applies only to banks. Its compliance review examines its own financing activities and regulator before deciding whether particular requirements cover it. The review is documented so that the conclusion can be explained later.

3

Example

A firm publishes a detailed privacy statement but gives broad internal access to customer records. The security review identifies that disclosure wording and access safeguards are separate duties. Access is narrowed to the staff who need the records for their work.

Formula

Calculation

There is no single GLBA compliance percentage. An illustrative data review can compare identified customer-information systems with systems covered by the required controls. If twelve systems hold relevant information but only nine appear in the security inventory, three need investigation, a gap of 3 / 12 = 25% of the systems. That count is a starting point, not evidence that nine systems comply or that all twelve fall under the same rule. Coverage, notices, access, service providers and incident handling each need their own assessment. Access can be counted in the same way. If 40 employees can open customer files but a role review shows that only 25 need them to do their jobs, 40 - 25 = 15 employees, or 15 / 40 = 37.5%, hold access that should be justified or removed.

Case study

Seen in the real world.

Fictional case study: Harbor Lending introduced an outsourced document-processing service to speed loan applications. Its privacy notice remained unchanged and several operations staff could download all customer files. The compliance team mapped the new data flow and checked the rules applying to the firm. Security staff reviewed access and the service-provider arrangement. They found that a current notice alone would not answer the safeguards questions, while technical controls alone would not explain sharing practices to customers.

Harbor updated the relevant processes and retained evidence of the review. It treated GLBA as a set of defined responsibilities rather than a generic privacy badge. The work also checked other applicable rules, preventing one law's name from being used as a complete answer to the firm's data obligations. Harbor now repeats the data-flow mapping whenever it adds a vendor or changes how customer files are stored.

Watch out

Common mistakes.

  • Assuming the law applies only to banks. Covered activities and regulator responsibilities can include other financial businesses.
  • Treating a privacy notice as a security programme. Disclosures and practical safeguards address different parts of the obligation.
  • Promising that consumers can block every disclosure. Sharing rules include conditions and exceptions that need accurate explanation.

Questions

People also ask.

Does GLBA concern only information privacy?

No. It also has a historical role in financial-service regulation. Privacy and safeguards are important operational aspects, but not the whole law.

Does using a service provider remove responsibility?

No. Applicable oversight and safeguarding duties still need review. Outsourcing changes the data flow rather than making it irrelevant.

What should a manager do first?

Determine whether the activity is covered, identify the responsible regulator and map relevant information. Then assess the specific requirements against actual practices.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.