The Gramm-Leach-Bliley Act (GLBA) requires financial institutions — including many fintechs — to protect customer financial information and provide privacy notices. This guide explains GLBA's key requirements and how they apply to fintechs.
What Is GLBA for Fintechs? The Gramm-Leach-Bliley Act Explained
Data privacy in financial services is a federal legal requirement, not just a best practice. The Gramm-Leach-Bliley Act has governed how financial institutions handle customer data since 2000 — and it applies to many fintechs that founders don't realize are covered.
What Is GLBA?
The Gramm-Leach-Bliley Act (GLBA), also known as the Financial Services Modernization Act of 1999, requires financial institutions to explain how they share and protect customers' private financial information. It has three key components:
The Financial Privacy Rule — governs collection and disclosure of customers' personal financial information
The Safeguards Rule — requires a comprehensive information security program
The Pretexting Provisions — prohibit obtaining customer information through false pretenses
Who Does GLBA Apply To?
GLBA applies to "financial institutions" — broadly defined to include any company offering financial products or services to individuals. The FTC's Safeguards Rule applies to non-bank financial companies including:
Payment processors
Money transmitters
Fintech lenders
Loan servicers
Real estate settlement services
If your fintech handles customers' personal financial information in connection with financial products, GLBA likely applies.
The Financial Privacy Rule
Requires you to provide customers with a clear privacy notice explaining:
What personal information you collect
How you share that information
What categories are disclosed to third parties
How customers can opt out of certain sharing
Customers must receive an initial notice at account opening and an annual notice thereafter.
The Safeguards Rule (Updated 2023)
Requires a comprehensive written information security program including:
Designation of a qualified security officer
A risk assessment identifying foreseeable threats
Technical, administrative, and physical safeguards
Regular monitoring and testing
For companies with 5,000+ customers, specific technical requirements apply including multifactor authentication, encryption in transit and at rest, access controls, audit logging, and an incident response plan.
Frequently Asked Questions
Is GLBA the same as GDPR?
No — GLBA is a US federal law focused on financial institutions. GDPR is a European regulation covering all personal data of EU residents. Both may apply if you have EU customers.
What are the penalties for GLBA violations?
Civil penalties up to $100,000 per violation. Officers and directors can face personal liability up to $10,000 per violation.
Does the Safeguards Rule apply to small fintechs?
Yes, with some modifications. Companies with fewer than 5,000 customers have reduced obligations under certain technical requirements, but the core requirements apply regardless of size.
This article is for educational purposes only and does not constitute legal or compliance advice. Consult a qualified compliance professional or legal counsel for guidance specific to your business.