Skip to content

The GLBA mandates the encryption of sensitive customer data both at rest and in transit. This is crucial for protecting confidential information like account numbers, Social Security numbers, and credit card details from unauthorized access.

The GLBA requires financial institutions to implement robust access controls to restrict access to customer data based on the principle of least privilege. This includes measures such as strong authentication, role-based access control, and regular access reviews.

Organizations need to have established information security programs that are based on continuous data risk assessments.

What is the Gramm Leach Bliley Act (GLBA)?

The Gramm-Leach-Bliley Act (GLBA) is a federal US law requiring financial services companies to keep customer and consumer data private and secure. Introduced in 1999, the GLBA affects companies that collect, use, and share personally identifiable information (PII), like banks, broker-dealers, asset managers, and insurance companies.

Companies must have robust security protocols to prevent unauthorized access, use, or disclosure of sensitive data to comply with GLBA. The GLBA requires financial services companies to give customers and consumers privacy notices explaining their data-sharing practices and allow them to opt out of certain types of data-sharing. The Securities and Exchange Commission (SEC) and the Federal Trade Commission (FTC) are regulators that enforce GLBA compliance.