GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
Deep expertise in the Gramm-Leach-Bliley Act (GLBA) for financial institutions and their service providers.
Expertise Areas
GLBA Overview
Full Name: Gramm-Leach-Bliley Financial Services Modernization Act of 1999
Authority: 15 U.S.C. 6801-6809
Also Known As: Financial Modernization Act, GLBA
Purpose: Protect consumers' personal financial information held by financial institutions
Regulatory Framework:
Federal Trade Commission (FTC): 16 CFR Part 313 (Privacy), 16 CFR Part 314 (Safeguards)
Banking Regulators: OCC, FDIC, Federal Reserve, NCUA (banks, credit unions)
Securities and Exchange Commission (SEC): Broker-dealers, investment advisors
State Insurance Commissioners: Insurance companies
CFTC: Commodity futures, derivatives
Effective Dates:
Original Act: November 12, 1999
Privacy Rule: July 1, 2001
Safeguards Rule: May 23, 2003
Amended Safeguards Rule: December 9, 2021 (compliance June 9, 2023)
Who Must Comply
"Financial Institution" Definition: Any institution engaged in "financial activities"
Covered Entities:
Depository Institutions:
Commercial banks
Savings banks
Credit unions
Thrifts
Securities Firms:
Broker-dealers
Investment advisors
Investment companies (mutual funds)
Transfer agents
Insurance Companies:
Life insurance
Property and casualty insurance
Insurance agents and brokers
Other Financial Services:
Mortgage lenders and brokers
Payday lenders
Finance companies
Collection agencies
Check cashing services
Wire transfer services
Tax preparation services (if offer RALs)
Real estate appraisers
Courier services (financial documents)
Credit counselors
Career counseling for finance jobs
FTC Jurisdiction: Financial institutions NOT regulated by banking/securities/insurance regulators
Service Providers: Must contractually commit to safeguarding customer information
Three Main Components
1. Financial Privacy Rule (16 CFR Part 313):
Requires privacy notices
Gives consumers opt-out rights
Restricts information sharing
2. Safeguards Rule (16 CFR Part 314):
Requires written information security program
Mandates specific security controls
Enforces vendor management
3. Pretexting Provisions (15 U.S.C. 6821):
Prohibits obtaining customer information under false pretenses
Requires institutions to protect against pretexting
Safeguards Rule (16 CFR Part 314)
Overview
Requirement: Develop, implement, and maintain comprehensive written information security program
Standard: "Administrative, technical, and physical safeguards" that are "appropriate" to size, complexity, nature, and scope of activities
Coverage: Protects "customer information" (current and former customers)
December 2021 Amendments
Major Changes:
Encryption of customer information at rest and in transit (new)
Multi-factor authentication for remote access (new)
Sharing with affiliates (but FCRA notice may be required)
Sharing with service providers (with confidentiality contract)
Sharing under joint marketing agreements
Sharing as permitted by law
Sharing to process transactions customer requested
Sharing to service/maintain accounts
Sharing to prevent fraud
Sharing with consumer reporting agencies
Sharing in connection with sale/merger
Opt-Out Mechanism:
Reasonable means (online, phone, mail)
Free of charge
Response time: Reasonable period (30 days standard)
Duration: Until consumer revokes (no expiration required)
Reuse and Redisclosure:
If receive NPI under exception, can only use for that purpose
Cannot redisclose except back to institution or under same exception
Account Number Restrictions
Prohibition: Cannot disclose account number or access code for credit card, deposit, or transaction account to nonaffiliated third party for marketing purposes
Exceptions:
To consumer reporting agencies
To service providers performing marketing for institution
To participant in private label/affinity card program
To agent/service provider solely to verify account accuracy
No Opt-Out: Prohibition is absolute; opt-out not sufficient
State Law Preemption
General Rule: GLBA preempts state laws only to extent inconsistent
Greater Protection: States can provide MORE privacy protection (not less)
Examples:
Vermont: Opt-in required for sharing with data brokers
California: CCPA/CPRA additional requirements
Massachusetts: 201 CMR 17.00 data security requirements
New York: NYDFS 23 NYCRR 500 cybersecurity regulation
Compliance Strategy: Meet GLBA + strictest applicable state law
Pretexting Provisions
Overview
Prohibition: Obtaining customer information from financial institution under false, fictitious, or fraudulent pretenses
Authority: 15 U.S.C. 6821
Criminal Penalties:
Fines up to $250,000 for individuals
Imprisonment up to 5 years
Fines up to $500,000 for organizations
What is Pretexting
Definition: Using false pretenses to obtain customer information
Examples:
Posing as customer to obtain account information
Posing as institution employee to trick customer service
Using stolen credentials to access customer data
Social engineering to extract information
Phishing for customer information
Prohibited Actions:
Use false statements or documents
Impersonate customer or institution
Use fraudulent statements to persuade disclosure
Use stolen or forged documents
Institution Responsibilities
Prevention Requirements:
Implement administrative, technical, and physical safeguards
Authenticate callers before releasing information
Train employees to recognize pretexting attempts
Procedures to verify third-party requests
Monitor for suspicious activity
Safeguards:
Multi-factor authentication before releasing information
Call-back verification procedures
Challenge questions
Documented authorization for third-party requests
Employee training on social engineering
Reporting: Report suspected pretexting to law enforcement and appropriate regulators
Regulatory Enforcement
Federal Trade Commission (FTC)
Jurisdiction: Financial institutions not regulated by banking, securities, or insurance regulators
Examples:
Mortgage brokers
Payday lenders
Check cashing services
Collection agencies
Tax preparers
Career counselors
Enforcement Actions:
Administrative complaints
Civil penalties up to $50,120 per violation per day (adjusted for inflation)
Injunctive relief
Compliance monitoring
Consumer redress
Recent FTC Enforcement Examples:
Drizly (2022): $2.5M penalty
Inadequate data security despite Safeguards Rule requirements
Failure to implement MFA
Poor vendor oversight
CEO held personally liable
Chegg (2022): Settlement
Four data breaches due to poor security
Misleading privacy claims
Failed to implement basic safeguards
20-year compliance monitoring
PayPal/Venmo (2018): Settlement
Misleading privacy claims about Venmo default settings
Inadequate privacy notice disclosures
TaxSlayer (2017): Settlement
Data breach due to inadequate security
Failed to implement multi-factor authentication
Inadequate employee training
Weak password policies
Banking Regulators
OCC, FDIC, Federal Reserve, NCUA: Regulate banks and credit unions
Standards: Similar to FTC Safeguards Rule but often more detailed
FFIEC Guidelines: Comprehensive security guidance
Interagency Guidelines: 12 CFR Part 30 Appendix B (OCC), similar for others
Higher Standards: Banks subject to additional requirements beyond GLBA