Back to Glossary
⚖️Compliance & Regulations

GLBA (Gramm-Leach-Bliley Act)

Quick Definition

A United States federal law requiring financial institutions to explain their information-sharing practices to customers and protect sensitive customer financial information.

What is GLBA (Gramm-Leach-Bliley Act)?

The Gramm-Leach-Bliley Act (GLBA), also known as the Financial Services Modernization Act of 1999, requires financial institutions to protect the security and confidentiality of customers' nonpublic personal information (NPI). GLBA applies to financial institutions including banks, credit unions, insurance companies, securities firms, and companies providing financial products or services to consumers.

GLBA contains three principal parts: The Financial Privacy Rule (requires privacy notices and gives consumers the right to opt-out of information sharing), The Safeguards Rule (requires written information security plans with administrative, technical, and physical safeguards), and The Pretexting Provisions (prohibits accessing private information through false pretenses). The FTC enforces GLBA for most non-bank financial institutions.

The Safeguards Rule requires financial institutions to develop a comprehensive information security program including: designating employees to coordinate the program, identifying and assessing risks to customer information, designing and implementing safeguards, regularly monitoring and testing programs, selecting service providers capable of maintaining safeguards, and updating the program as needed. Using customer financial data in test environments without proper masking violates GLBA safeguard requirements.

Common Use Cases

  • Banking application development
  • Insurance system testing
  • Financial services compliance
  • Fintech application security

Need help with GLBA (Gramm-Leach-Bliley Act)?

GoMask makes realistic synthetic datasets with the patterns you ask for. Get started in minutes.