The Gramm-Leach-Bliley Act (GLBA), also known as the Financial Services Modernization Act of 1999, is a US Federal law that primarily governs the handling and protection of consumers’ Nonpublic Personal Information (NPI) by financial institutions.
The act aims to ensure the privacy and security of sensitive financial data while enabling certain types of financial service integrations.
The three (3) main objectives of GLBA 501(b) are to:
The GLBA applies broadly to banks, insurance companies, securities firms and other financial institutions. Non-compliance can lead to regulatory penalties and loss of customer trust. For cybersecurity professionals, GLBA compliance means ensuring that adequate controls and policies are in place to safeguard sensitive customer data.
In accordance with GLBA, almost any organization that works with consumers’ money is considered a financial institution. Some inclusions are obvious (e.g. bank, credit union or brokerage). However, there are many less obvious inclusions as well. Some examples from the FTC include: