Blog Login
Compliance

Privacy Compliance for Fintechs: CCPA, GLBA, and What You Need to Know

A

Anzar Dewani

2 hours ago

Fintechs face overlapping privacy compliance obligations under the Gramm-Leach-Bliley Act (GLBA), the California Consumer Privacy Act (CCPA), and other state privacy laws. This guide explains what each framework requires, how they interact, and what a fintech privacy compliance program must include. Anzar Dewani

Privacy Compliance for Fintechs: CCPA, GLBA, and What You Need to Know

Fintechs collect and use significant amounts of personal financial data — and that data is subject to an increasingly complex web of federal and state privacy laws. The two most important frameworks for most US fintechs are the Gramm-Leach-Bliley Act (GLBA) at the federal level and the California Consumer Privacy Act (CCPA) at the state level. Understanding what each requires — and how they interact — is foundational to building a compliant privacy program.

The Gramm-Leach-Bliley Act (GLBA): Federal Financial Privacy

The Gramm-Leach-Bliley Act is the primary federal financial privacy law. It applies to financial institutions — including most fintechs that qualify as money services businesses or that offer financial products or services. GLBA has two main privacy components:

The Privacy Rule (Regulation P)

The Privacy Rule, implemented as Regulation P, requires financial institutions to:

  • Provide a privacy notice to customers at the time they establish a customer relationship and annually thereafter, explaining what nonpublic personal information (NPI) is collected, how it is used, and with whom it is shared
  • Allow opt-out of certain information sharing with non-affiliated third parties before sharing NPI with those parties (the opt-out right does not apply to sharing with affiliated companies or to certain service provider arrangements)
  • Limit sharing of NPI in accordance with the notice provided and the customer's opt-out choices

Nonpublic personal information under GLBA includes any information consumers provide to obtain a financial product or service, any information about transactions with the institution, and any other information that is not publicly available. For fintechs, this covers virtually all customer financial data.

The Safeguards Rule

The FTC's Safeguards Rule (updated in 2023) requires non-bank financial institutions — including most fintechs — to implement a comprehensive written information security program to protect customer NPI. The updated Safeguards Rule requires:

  • Designation of a qualified individual to oversee the information security program
  • A written risk assessment of security risks to customer information
  • Implementation of specific technical safeguards, including multi-factor authentication, encryption of customer data in transit and at rest, and access controls
  • Continuous monitoring and testing of the security program
  • Incident response plan for security events
  • Annual reporting to the board of directors (or equivalent) on the information security program
  • Notification to the FTC within 30 days of a security breach affecting 500 or more customers

The Safeguards Rule applies to financial institutions subject to FTC jurisdiction — which includes most non-bank fintechs. The 2023 updates significantly expanded the rule's technical requirements. See our detailed guide on GLBA for fintechs for the full framework.

The California Consumer Privacy Act (CCPA) and CPRA

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most comprehensive US state privacy law and applies to many fintechs that serve California consumers. The CCPA/CPRA is enforced by the California Privacy Protection Agency (CPPA).

Who Must Comply with CCPA?

The CCPA applies to for-profit businesses that do business in California and meet one or more of the following thresholds:

  • Annual gross revenues exceeding $25 million
  • Annually buy, sell, or share the personal information of 100,000 or more consumers or households
  • Derive 50% or more of annual revenues from selling or sharing consumers' personal information

Many fintechs serving California customers — particularly those with significant transaction volumes — will meet these thresholds.

CCPA Rights and Fintech Obligations

Under CCPA, California consumers have specific rights that fintechs must honor:

  • Right to know: Consumers can request disclosure of what personal information the business collects, uses, shares, and sells
  • Right to delete: Consumers can request deletion of their personal information (subject to certain exceptions)
  • Right to opt out of sale or sharing: Consumers can opt out of the sale or sharing of their personal information for cross-context behavioral advertising
  • Right to correct: Consumers can request correction of inaccurate personal information
  • Right to limit use of sensitive personal information: Consumers can limit use of sensitive personal information — which for fintechs includes financial account data and precise geolocation
  • Right to non-discrimination: Businesses cannot discriminate against consumers who exercise their CCPA rights

GLBA Exemption Under CCPA

CCPA includes a partial exemption for personal information subject to GLBA. Personal information that is collected, processed, sold, or disclosed pursuant to GLBA and its implementing regulations is exempt from CCPA's consumer rights provisions. However, the CCPA's anti-discrimination provisions and certain other requirements still apply.

For fintechs, this means that NPI collected in the course of providing financial services is largely GLBA-governed, while other personal information — marketing data, device identifiers, browsing behavior — may be subject to CCPA. The line between what is and is not covered by the GLBA exemption requires careful legal analysis.

Other State Privacy Laws Fintechs Must Watch

Following California's lead, many other states have enacted comprehensive privacy laws that fintechs must monitor:

  • Virginia Consumer Data Protection Act (VCDPA)
  • Colorado Privacy Act (CPA)
  • Connecticut Data Privacy Act (CTDPA)
  • Texas Data Privacy and Security Act (TDPSA)
  • Oregon Consumer Privacy Act (OCPA)

Each state law has its own thresholds, exemptions (including financial institution exemptions that may be broader or narrower than CCPA's), and consumer rights. Fintechs with customers in multiple states should conduct a state-by-state privacy law assessment.

Building a Fintech Privacy Compliance Program

A practical fintech privacy compliance program covers several core areas:

  • Data inventory and mapping: Understanding exactly what personal and financial data you collect, where it is stored, how it is used, and with whom it is shared
  • Privacy notices: Maintaining accurate, up-to-date GLBA privacy notices and CCPA privacy disclosures
  • Consumer rights processes: Procedures for responding to consumer requests under CCPA and applicable state laws within required timeframes
  • Vendor management: Ensuring that third-party vendors who receive customer data are contractually required to protect it
  • Incident response: Written plan for responding to data breaches, including notification obligations to regulators and affected consumers
  • Safeguards Rule compliance: Technical security program meeting FTC Safeguards Rule requirements

Frequently Asked Questions

Does GDPR apply to US fintechs?

GDPR applies to any organization that processes the personal data of individuals located in the EU, regardless of where the organization is based. US fintechs that serve EU customers, have EU employees, or monitor EU individuals' behavior must comply with GDPR. The consequences of non-compliance can include fines of up to 4% of global annual revenue. Fintechs with any EU exposure should conduct a GDPR assessment.

What is the difference between GLBA and CCPA for a fintech?

GLBA is a federal law focused specifically on financial privacy — it governs the collection and sharing of financial customers' nonpublic personal information and requires security safeguards. CCPA is a broader state privacy law that covers all personal information, provides extensive consumer rights, and is enforced by a dedicated state agency. The two frameworks overlap but are not duplicative — fintechs must comply with both.

Does my fintech need a Chief Privacy Officer?

There is no universal federal requirement for a Chief Privacy Officer. However, the FTC Safeguards Rule requires designation of a qualified individual to oversee the information security program, and CCPA regulations require designation of a privacy contact. At larger fintechs, privacy responsibility is often centralized in a dedicated CPO or privacy function.

 

This article is for educational purposes only and does not constitute legal or compliance advice. Privacy laws are complex and subject to change. Consult qualified legal counsel for guidance specific to your business.

 

Talk to the ComplyOne team to get started.

Share this article:

Related Articles