Skip to content

GLBA

What is GLBA?

The Gramm-Leach-Bliley Act requires financial institutions to explain their data sharing practices and protect sensitive consumer financial information.

Compliance and Regulatory

Each of these is named in at least one of the same controls as glba. The number is how many controls name both.

What the standards actually require on glba

Requirements naming glba across 6 standards, quoted from the control text.

GLBA12 controls

GLBA Section 6801 - Protection of nonpublic personal information. SUBSECTION (a) PRIVACY OBLIGATION POLICY: it is the policy of Congress that each financial institution has an AFFIRMATIVE AND CONTINUING OBLIGATION to respect the privacy of its customers + to p...

GLBA-Sec6801-PolicyDuty-SafeguardingStandard · GLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard

Florida FDBR coordination with sectoral federal privacy + data protection laws. COPPA (Children Online Privacy Protection Act, 15 USC 6501 + 16 CFR Part 312): FTC-administered; covers online services collecting from children under 13;

FDBR-Coord-COPPA-FERPA-HIPAA-Sectoral · Coordination with COPPA, FERPA, HIPAA, GLBA, FCRA and Sectoral Federal Laws

Coordination positions INCDPA within the broader US and international privacy regulatory landscape. (1) US State Privacy Law Patchwork: 20+ comprehensive US state privacy laws as of 2026 (California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Conne...

INCDPA-Coord-USStatePrivacy-VCDPA-CPA-CTDPA-CCPA-Federal-FTC-DPDP-GDPR-International · Indiana CDPA Coordination - US State Privacy Laws (Virginia/Colorado/Connecticut/Utah/Texas/Iowa+) + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International Privacy Frameworks

Coordination positions ICDPA within the broader US and international privacy regulatory landscape. (1) Utah UCPA Template Parent: Iowa CDPA most closely follows Utah CDPA (UCPA effective 31 December 2023) template - shared narrow Sale definition + opt-out (NOT...

ICDPA-Coord-USStatePrivacy-UCPA-Template-VCDPA-CPA-CTDPA-Federal-FTC-GDPR-International · Iowa CDPA Coordination - Utah CDPA Template Parent + US State Privacy Patchwork + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International

Institutions participating in Title IV federal student aid programmes are financial institutions under GLBA.

HE-1 · Financial institution status of higher education

16 CFR 314.1 purpose + scope; 314.2 definitions. PURPOSE: to establish standards for safeguarding customer information held by financial institutions under FTC jurisdiction + implementing Title V of GLBA.

FTC-Safeguards-Scope-Defs · Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

Questions people ask about glba

What is GLBA?
The Gramm-Leach-Bliley Act requires financial institutions to explain their data sharing practices and protect sensitive consumer financial information.
Why is GLBA important for compliance?
GLBA is a key concept in Compliance and Regulatory. Understanding glba helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address GLBA?
GLBA appears in the requirement text of GLBA, Florida Digital Bill of Rights (FDBR), Indiana Consumer Data Protection Act, Iowa Consumer Data Protection Act, US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule. Across these standards we have identified 30 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about GLBA?
Explore our compliance framework pages to see how glba applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how GLBA applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.