Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Gramm-Leach-Bliley Act (GLBA)

The Financial Services Modernization Act of 1999 (Gramm-Leach-Bliley Act) (GLBA) includes provisions to protect consumers' personal financial information held by financial institutions. As part of its implementation of GLBA, the Federal Trade Commission (FTC) issued the Safeguards Rule under section 501(b), requiring financial institutions under FTC jurisdiction to secure customer records and information.

The three main objectives of GLBA 501(b) are to:

  • Ensure the security and confidentiality of customer records and information
  • Protect against any anticipated threats or hazards to the security or integrity of such records
  • Protect against unauthorized access or use of such records or information which could result in substantial harm or inconvenience to any customer.
Key Takeaways - GLBA Compliance
  • GLBA (1999) requires financial institutions to protect consumers' personal financial information through a written security program.
  • Three core objectives. Ensure security and confidentiality, protect against anticipated threats, and prevent unauthorized access.
  • The Safeguards Rule (effective 2003) requires proactive security measures including risk assessment, safeguard implementation and monitoring.
  • The FTC uses an extremely broad definition of financial institution. Including tax preparers, credit counselors, real estate settlement services and debt collectors.
  • The FFIEC provides an Information Security Handbook with 20 plus tests specifically for intrusion prevention and detection.
  • Failure to comply has serious consequences for both individuals and organizations.
GLBA Focus

Overview Of GLBA

In accordance with GLBA, almost any organization that works with consumers’ money is considered a financial institution. Some inclusions are obvious (e.g. bank, credit union or brokerage). However, there are many less obvious inclusions as well.

Some examples from the FTC include:

  • Ensure the security and confidentiality of customer records and information
  • Protect against any anticipated threats or hazards to the security or integrity of such records
  • Protect against unauthorized access or use of such records or information which could result in substantial harm or inconvenience to any customer.

In addition to the direct providers of those services, any organization that receives data from those providers must also comply with GLBA requirements. The FTC uses an extremely broad definition of the term "financial institution" for the purposes of GLBA

GLBA Compliance

Safeguards Rule

The Safeguards Rule, which went into effect in 2003, requires that included institutions take proactive steps to ensure the security of customer information.

At a minimum, institutions must:

  • Appoint an individual or group to bear specific responsibility for GLBA compliance.
  • Identify risks to customer information and assess existing safeguards.
  • Implement safeguards that are needed to fill any gaps.
  • Monitor the effectiveness of all safeguards.
  • Ensure service providers are capable of meeting GLBA requirements.
  • Adjust the organization's security program as necessary when circumstances change.

Compliance with the GLBA is a serious matter. Failure to comply has serious consequences for individuals and organizations found guilty.

Federal Financial Institutions Examination Council (FFIEC)

FFIEC Security Process

The Federal Financial Institutions Examination Council (FFIEC), comprised of examiners from many different regulatory bodies tasked with GLBA enforcement, has created an Information Security Handbook and an exhaustive set of tests to assess compliance with the Safeguards Rule, including over 20 specifically related to intrusion prevention and detection.

The security process recommended by the FFIEC comprises five key areas:

  • Information Security risk assessment
  • Information Security strategy
  • Implement security controls
  • Security testing
  • Monitoring and updating
Common Questions

Frequently-Asked Questions

Here are answers to common questions about GLBA compliance:

What does GLBA Section 501(b) require?
Section 501(b) of the Gramm-Leach-Bliley Act, codified at 15 U.S.C. 6801(b), directs federal agencies to set administrative, technical and physical safeguard standards for the financial institutions they oversee. Those safeguards must ensure the security and confidentiality of customer records and information, protect against anticipated threats or hazards to their security or integrity, and protect against unauthorized access or use that could cause substantial harm or inconvenience to any customer. The FTC implements this through its Safeguards Rule.
What are the requirements of the FTC Safeguards Rule?
The Safeguards Rule requires a written information security program built on nine elements. A covered institution must designate a Qualified Individual, conduct written risk assessments, implement safeguards such as access controls, encryption and multi-factor authentication, monitor and test those safeguards, train staff, oversee service providers, keep the program current, maintain a written incident response plan, and have the Qualified Individual report to the board at least annually. For the risk assessment and incident response elements, you can use ComplianceForge's Cybersecurity Risk Assessment (CRA) Template and Integrated Incident Response Program (IIRP).
Which businesses count as financial institutions under the Safeguards Rule?
The Safeguards Rule covers financial institutions under FTC jurisdiction, a group that reaches well beyond banks. Examples listed in 16 CFR 314.2 include mortgage brokers, tax preparation firms, automobile dealerships that lease vehicles for longer than 90 days, check printers, wire transfer services, and real estate settlement service providers. Banks follow the safeguarding standards issued by their own federal banking regulators instead of the FTC rule.
Does GLBA require reporting data breaches to the FTC?
Yes, for institutions covered by the FTC Safeguards Rule. Since May 13, 2024, a notification event involving the information of at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery, using the FTC's online form. A notification event is the unauthorized acquisition of unencrypted customer information. The requirement appears in 16 CFR 314.4(j).
Are small businesses exempt from the GLBA Safeguards Rule?
Not entirely. Under 16 CFR 314.6, a financial institution that maintains customer information on fewer than 5,000 consumers is exempt from only a few provisions: the written risk assessment, certain continuous monitoring or penetration testing requirements, the written incident response plan, and the annual written report to the board. It must still designate a Qualified Individual, implement safeguards such as encryption and multi-factor authentication, train staff, and oversee service providers.