Blog Login
Consumer Protection

What Is GLBA for Fintechs? The Gramm-Leach-Bliley Act Explained

A

Anzar Dewani

1 hour ago

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions — including many fintechs — to protect customer financial information and provide privacy notices. This guide explains GLBA's key requirements and how they apply to fintechs.

What Is GLBA for Fintechs? The Gramm-Leach-Bliley Act Explained

Data privacy in financial services is a federal legal requirement, not just a best practice. The Gramm-Leach-Bliley Act has governed how financial institutions handle customer data since 2000 — and it applies to many fintechs that founders don't realize are covered.

What Is GLBA?

The Gramm-Leach-Bliley Act (GLBA), also known as the Financial Services Modernization Act of 1999, requires financial institutions to explain how they share and protect customers' private financial information. It has three key components:

The Financial Privacy Rule — governs collection and disclosure of customers' personal financial information

The Safeguards Rule — requires a comprehensive information security program

The Pretexting Provisions — prohibit obtaining customer information through false pretenses

Who Does GLBA Apply To?

GLBA applies to "financial institutions" — broadly defined to include any company offering financial products or services to individuals. The FTC's Safeguards Rule applies to non-bank financial companies including:

Payment processors

Money transmitters

Fintech lenders

Loan servicers

Real estate settlement services

If your fintech handles customers' personal financial information in connection with financial products, GLBA likely applies.

The Financial Privacy Rule

Requires you to provide customers with a clear privacy notice explaining:

What personal information you collect

How you share that information

What categories are disclosed to third parties

How customers can opt out of certain sharing

Customers must receive an initial notice at account opening and an annual notice thereafter.

The Safeguards Rule (Updated 2023)

Requires a comprehensive written information security program including:

Designation of a qualified security officer

A risk assessment identifying foreseeable threats

Technical, administrative, and physical safeguards

Regular monitoring and testing

For companies with 5,000+ customers, specific technical requirements apply including multifactor authentication, encryption in transit and at rest, access controls, audit logging, and an incident response plan.

Frequently Asked Questions

Is GLBA the same as GDPR?

No — GLBA is a US federal law focused on financial institutions. GDPR is a European regulation covering all personal data of EU residents. Both may apply if you have EU customers.

What are the penalties for GLBA violations?

Civil penalties up to $100,000 per violation. Officers and directors can face personal liability up to $10,000 per violation.

Does the Safeguards Rule apply to small fintechs?

Yes, with some modifications. Companies with fewer than 5,000 customers have reduced obligations under certain technical requirements, but the core requirements apply regardless of size.

 

This article is for educational purposes only and does not constitute legal or compliance advice. Consult a qualified compliance professional or legal counsel for guidance specific to your business.

 

Talk to the ComplyOne team to get started.

Share this article: