Ensure GLBA compliance with RecordPoint

The Gramm-Leach-Bliley Act (GLBA) is a U.S. federal law passed in 1999 that governs how financial institutions have to protect consumer financial data.RecordPoint empowers financial services companies to comply with the data privacy provisions of GLBA and other important laws.

How RecordPoint can help

RecordPoint can help U.S. companies facilitate their GLBA compliance with several key features, including:

Know exactly where sensitive data lives

Visibility into your data is the foundation of GLBA compliance. RecordPoint connects to hundreds of business systems, automatically finding and classifying information across structured and unstructured sources — so you always have a clear picture of what you hold and how sensitive it is.

Dispose of the data you no longer need

GLBA's Safeguards Rule requires financial institutions to keep customer data only as long as necessary and have documented procedures for disposing of it securely. RecordPoint enforces retention schedules automatically, triggers a review when the retention period ends, and routes every disposal through an approval workflow — so your policy is one you can prove.

Evidence-ready compliance, built in from the start

GLBA doesn't just require a retention policy — it requires evidence that the policy is being reviewed and acted on. RecordPoint logs every retention decision and disposal action with a timestamped audit trail, giving you the documentation to show regulators your information security program is functioning as intended.

About the Gramm-Leach-Bliley Act

The Gramm-Leach-Bliley Act (GLBA), also known as the Financial Services Modernization Act, was passed on November 12, 1999. It implemented several new rules related to the protection of consumer financial information for financial services companies like banks, credit unions, and insurance companies.

The GLBA rules:

  • The Financial Privacy Rule – This rule governs the collection and disclosure of private financial information. It also provides for the dissemination of privacy notices that clearly communicate how the institution uses the data it collects.
  • The Safeguards Rule – The rule that requires financial institutions to implement security programs designed to protect private customer information. The rule states that financial institutions have to deploy administrative, technical, and physical safeguards to protect personal data from internal and external threats. These protections need to be documented in an information security program.
  • The Pretexting Rule – This rule prohibits accessing private financial information under false pretenses. In practice, this is called "pretexting," and is especially crucial to understand with the rise in phishing attacks. Financial institutions follow this rule by training their employees to spot phishing attempts.

The GLBA is named for Senator Phil Gramm (R, Texas), Congressman Jim Leach (R, Iowa), and Congressman Thomas J. Bliley, Jr. (R, Virginia) – the three legislators most directly associated with the bill. GLBA did several things beyond implementing new rules related to protecting consumer financial information.

GLBA repealed large portions of the Glass-Steagall Banking Act of 1933 and the Bank Holding Company Act of 1956, allowing banks, brokerages, and insurance companies to merge. Part of getting the act passed meant adding the three new rules around protecting consumer financial information.

The purpose of the GLBA is to ensure that banks and other financial institutions protect consumer information with effective security programs, beyond enabling organizations that previously had to remain separate to merge. Regulatory updates have shifted standards for the GLBA in recent years. The Privacy Rule previously required notification of data breaches for incidents including 1,000 customers; it has since been dropped to incidents including 500 customers.

Right to be informed about how their data is being used, stored, and processed
Right to access personal data that data controllers possess
Right to rectify incorrect personal data that businesses hold
Right to erasure (to have a business delete the data it holds)
Right to data portability (to use their personal data for different services)
Right to prior consent
Right to withdraw consent to information collection at any time
Right to complain to the Information Commissioner
Right to not be subjected to automated decision-making

    How can businesses comply with the GLBA?

    There are specific steps that financial services companies need to take to comply with GLBA, which include:

    1
    Identify protected information

    First, identify all the non-public information (NPI) you have and where it lives – cataloging and storing your data in in a secure and scalable, cloud-based data inventory makes it easier to monitor. Next, evaluate your security measures – banks must have a system in place for protecting NPI to ensure GLBA compliance.

    2
    Assess organizational risk

    There are many possible vulnerabilities that could put customer data at risk, which might include outdated systems that create tech debt, data encryption that lags standards, or weak access controls. A full evaluation ensures financial IT security groups can determine how likely a possible breach might be.

    3
    Document an information security program

    To comply with the Safeguards Rule, financial institutions need to create and document an information security program. That meets these standards:

    • Appoint a qualified expert or team
    • Document the findings
    • Outline the safeguards
    • Create an incident response plan
    • Select secure third-party vendors
    • Outline security awareness training for employees
    4
    Provide privacy notices

    Providing privacy notices is a key facet of GLBA compliance. Notices should explain how and why customer data is collected, as well as provide instructions for them to "opt out" of data sharing practices like disclosure to non-affiliated third parties. Opt-out rights are also governed by the Fair Credit Reporting Act (FCRA).

    5
    Implement Safeguards

    The most effective safeguards include:

    • Access controls: Limit who can see NPI and for what purposes
    • Data encryption: Implement encryption techniques to ensure data is secure at rest and transit
    • Secure disposal: Defensibly dispose of data at the right time
    • Multi-Factor Authentication: Require MFA to access sensitive data
    • Inventory management security: Use cloud-based solutions to identify, classify, and label NPI
    6
    Monitor and update your program

    Companies must test, monitor, and update the information security program regularly. Adopting a proactive mindset can take the shape of regular penetration tests and risk assessments, which is the best way to prevent breaches, respond faster to incidents, minimize downtime, and protect sensitive data.

    Penalties for noncompliance

    Up to
    $100,000
    Imprisoned
    for up to 5 years

    The penalties for non-compliance can be significant; companies can be fined $100,000 for each violation, and individuals charged and imprisoned for up to five years. That’s why leaders and key decision-makers must prioritize GLBA compliance.

    Frequently asked questions

    What agency manages compliance with GLBA?
    What kind of data is covered under the GLBA?
    What businesses are covered under the GLBA?
    Have more questions about GLBA compliance or looking for additional details? Reach out to our friendly team - we're happy to help you navigate it.
    Contact Us