FIN-02 · 01
GLBA Privacy Notices and the Safeguards Rule for Financial Technology Companies
GLBA runs on two tracks that are often confused: what you must tell customers about data sharing, and what you must build to protect the data. This brief separates them and lists what each demands.
- Coverage turns on activity, not on holding a bank charter. A company significantly engaged in financial activities can be a financial institution under GLBA.
- The privacy track requires an initial notice, an opt-out where nonaffiliated sharing triggers one, and an annual notice unless a statutory exception applies.
- The Safeguards Rule requires a written program with a named qualified individual, risk assessment, access controls, encryption, MFA, monitoring, training, and vendor oversight.