Scrutineer.ai
All posts
Guides

What is GLBA Compliance and Who Must Comply

GLBA does not apply to banks alone. It reaches tax preparers, collection agencies, car dealerships that arrange financing and Title IV universities, and which regulator supervises you decides whether MFA and annual penetration testing are mandatory or merely advisable. Here is who is covered, how to tell, and what the rule actually requires.

By the Scrutineer team

August 2026 · 10 min read

Try it while you read

No account, nothing to install.

Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.

The Scrutiny Desk

Illustrative sample · not an audit attestation

Last updated August 2026. GLBA compliance means meeting the obligations the Gramm-Leach-Bliley Act places on businesses that handle nonpublic personal information about consumers. It has three parts: the Privacy Rule, which governs the notices you give and the opt-out you offer; the Safeguards Rule, which governs the security programme protecting that data; and the pretexting provisions, which prohibit obtaining customer information under false pretenses. The part that generates almost all the work, and all the audit findings, is the Safeguards Rule.

The bigger surprise is who has to do it. GLBA does not apply to banks alone. It applies to any business significantly engaged in activities that are financial in nature, which sweeps in tax preparers, collection agencies, car dealerships and universities. Plenty of them find out during an audit. This guide covers who is covered, how to tell whether you are, which regulator writes your rule, and what compliance actually requires.

Who must comply with GLBA?

Section 314.2(h) of the FTC rule lists thirteen examples of businesses that count as financial institutions. The list is broader than the phrase suggests, because the test is the activity, not the industry label on your website.

Covered business Why it is covered
Mortgage lenders and mortgage brokersExtending credit and servicing loans are financial activities in their own right
Payday lenders and finance companiesConsumer lending
Account servicers and check cashersServicing accounts and cashing instruments for consumers
Wire transferorsTransmitting money on behalf of consumers
Collection agenciesCollecting consumer debt on behalf of creditors
Credit counselors and other financial advisorsAdvising consumers on financial matters
Tax preparation firmsPreparing returns is treated as a financial activity, which catches most accounting practices
Non-federally insured credit unionsOutside NCUA supervision, so the FTC picks them up
Investment advisers not required to register with the SECAdvisers below the SEC registration threshold fall to the FTC rather than to Reg S-P
FindersAdded by the 2021 amendments: businesses that bring buyers and sellers together and let them transact
Motor vehicle dealers that extend or arrange creditA dealership that arranges financing is a financial institution; one that only takes cash is not
Title IV colleges and universitiesCovered through the Program Participation Agreement rather than the FTC rule directly
Travel agencies operated in connection with financial servicesThe connection to a financial service, not the travel, is what triggers coverage

Two entries on that list account for most of the confusion. Tax preparation firms are covered, which means a four-person CPA practice carries the same Safeguards Rule obligations as a mortgage lender. And a car dealership that arranges financing is covered, while the same dealership selling only for cash is not. The activity decides it.

How do I know if my business is covered?

Three questions settle it in most cases. First, do you engage in an activity that is financial in nature, meaning lending, servicing, advising, transmitting, collecting, or arranging any of those? Second, do you obtain information about consumers in connection with providing that service? Third, is that a meaningful part of what you do rather than an incidental one-off? Three yeses put you in scope.

A useful sanity check: if you hold a file on an individual that exists only because they wanted a financial product or service from you, GLBA is probably in play. That includes the file itself, the fact of the relationship, and any list you derive from it. Underwriting is the clearest case of all, because the document package a lender assembles to make a credit decision is nonpublic personal information from the first page to the last.

What is nonpublic personal information under GLBA?

Nonpublic personal information is personally identifiable financial information a consumer gives you to obtain a financial product or service, information about a transaction between you and that consumer, or anything else you obtain in connection with providing the service. It also covers any list derived from that information. Publicly available information is excluded on its own.

The derived-list point catches people out. A list of your customers built entirely from public phone directories is still nonpublic personal information, because the fact that these particular people are your customers is not public. The data can be ordinary; the relationship is what makes it protected.

Which regulator writes my GLBA rule?

This is the question that decides what you actually have to build, and it is the one most GLBA checklists skip. Section 505(a) of the Act assigns enforcement to whichever agency already supervises you, and those agencies wrote materially different rules.

If you are a non-bank financial institution, you are under the FTC Safeguards Rule at 16 CFR Part 314, which is the most prescriptive of them. It names multi-factor authentication, encryption in transit and at rest, and either continuous monitoring or annual penetration testing plus semiannual vulnerability assessments. If you are a bank or credit union, you are under the interagency guidelines instead, which set risk-based objectives and name almost no specific technology. Broker-dealers and SEC-registered advisers are under Regulation S-P. Insurers answer to their state commissioner. Universities in the Title IV programmes are held to the FTC rule text through their Program Participation Agreement.

The practical consequence is blunt: two firms of identical size doing similar work can have genuinely different obligations, and MFA is mandatory for one and merely advisable for the other. Our GLBA compliance software page carries a full reference table of every regulator, rule citation, and notification clock, so you can find your row before you write a single control.

What are the GLBA compliance requirements?

Taking the FTC Safeguards Rule as the reference point, 16 CFR 314.4 requires a written, comprehensive information security programme built around nine elements. Designate a qualified individual to run it. Perform a written risk assessment and keep it current. Implement safeguards, including access controls, an inventory of where customer information lives, encryption, secure development, MFA, secure disposal, change management and activity monitoring. Test those safeguards. Train your people. Oversee your service providers. Maintain a written incident response plan. Report to the board at least annually.

Two of those are where firms most often fall down. The written risk assessment has to be genuinely written, dated, and specific to your environment, not a downloaded template with your name in the header. And service provider oversight means selecting providers capable of maintaining safeguards, requiring those safeguards by contract, and periodically assessing them. A clause in a signed contract with no assessment behind it is the single most common finding, which is why the same evidence base tends to serve both GLBA and a wider third-party risk management programme.

Does GLBA require breach notification?

Yes, but the duty and the clock depend on your regulator. Since May 13, 2024 the FTC Safeguards Rule requires notifying the FTC as soon as possible and no later than 30 days after discovering that unencrypted customer information of at least 500 consumers was acquired without authorization. Information counts as unencrypted for this purpose if the encryption key was accessed too.

SEC Reg S-P takes a different shape: covered entities must notify affected individuals within 30 days, with compliance running from December 3, 2025 for larger entities and June 3, 2026 for smaller ones. The banking agencies work from the 2005 interagency response programme guidance, which applies a reasonable-time standard rather than a fixed consumer threshold. Firms carrying more than one registration can be under more than one clock at once.

What happens if you violate GLBA?

There is no consumer right to sue under GLBA itself, so enforcement runs through your regulator. For FTC-supervised firms that means an investigation and, typically, a consent order imposing a mandated security programme and years of independent third-party assessments. The assessment obligation is usually the expensive part, not the headline penalty.

Banking institutions face examination findings and supervisory action. SEC-registered firms face examination deficiencies and enforcement. Title IV institutions face something more immediate: since June 9, 2023 Safeguards Rule compliance is tested in the annual Federal Single Audit, and a failure becomes an audit finding referred to the FTC and the Federal Student Aid Cybersecurity Team, with participation in the student aid programmes ultimately at stake.

Is there a GLBA compliance certification?

No. No agency certifies or approves an organization or a product as GLBA compliant, and no third party can issue a certificate carrying regulatory weight. Compliance is a property of how your programme is designed and operated, judged by your examiner or auditor when they look. A vendor can honestly say its product supports GLBA control requirements, and that is a fair claim. A certificate offered as proof of compliance is marketing.

What does travel well is evidence. If you can show a dated risk assessment, an access review with the joiner and leaver record behind it, a penetration test inside the year, training completion by name, and an assessment of each service provider, you can answer nearly anything an examiner asks. That is also why teams already running SOC 2 or ISO 27001 usually find GLBA cheaper than expected: the controls overlap heavily, and the work is mapping what you have to the rule you are under rather than starting again.

Where to start

Confirm which rule governs you before anything else, because a control list built from the wrong rule text is wasted effort and it happens constantly. Then inventory where customer information actually sits, since the Safeguards Rule requires that inventory explicitly and most firms discover the data is in more places than the diagram shows.

From there, name your qualified individual, write and date the risk assessment, and work the nine elements against what you already run rather than against a blank page. Most organizations already have perhaps two thirds of it operating somewhere. The gap is usually not the controls. It is being able to prove they were running last quarter as well as this morning.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.