Skip to content

Glossary · Compliance & Regulation

Gramm-Leach-Bliley Act (GLBA)

Short answer

The Gramm-Leach-Bliley Act (GLBA) is the U.S. law requiring financial institutions to explain how they share customer information and to protect it. Its Privacy Rule covers notices and opt-outs, and its Safeguards Rule requires a written information security program.

Gramm-Leach-Bliley Act (GLBA) explained

GLBA applies broadly to companies that offer financial products or services to consumers, including banks, lenders, brokers, insurers and many fintechs. The FTC's updated Safeguards Rule, which covers non-bank financial institutions, requires a qualified individual to oversee security, risk assessments, encryption, multi-factor authentication, service provider oversight and, since 2024, notification to the FTC of certain breaches affecting 500 or more consumers. Banks and SEC-registered firms meet similar requirements through their own regulators' rules, such as Regulation S-P.

CRM systems hold much of the nonpublic personal information GLBA protects, so access control and encryption there matter.

How Vantage Point helps: we configure access, encryption and audit controls in Salesforce and HubSpot to support GLBA safeguards.

Frequently asked questions

Does GLBA apply to fintech companies?

Often yes. Non-bank companies offering consumer financial products or services are typically covered by the FTC's GLBA rules.

What is nonpublic personal information?

Personally identifiable financial information a firm collects about a consumer in connection with a financial product or service, such as account numbers, balances and income.

Last reviewed October 2, 2026 by the Vantage Point team. Browse all glossary terms →