The Gramm-Leach-Bliley Act requires covered financial institutions to send each customer a clear privacy notice at least once in every twelve-month period, describing what nonpublic personal information the institution collects, who it shares that information with, how customers can opt out of certain sharing, and how the institution protects the data.1Board of Governors of the Federal Reserve System. Gramm-Leach-Bliley Act, Title V, Subtitle A Disclosure of Nonpublic Personal Information A 2015 amendment carved out an exception: institutions that share information only through channels that don’t trigger an opt-out right, and that haven’t changed the practices they most recently disclosed, can stop sending the annual notice entirely.
Who Has to Send an Annual Privacy Notice
The requirement reaches well beyond banks. A “financial institution” under Regulation P is any entity significantly engaged in financial activities, and the category picks up mortgage lenders, payday lenders, finance companies, check cashers, wire transfer services, collection agencies, credit counselors, tax preparation firms, and investment advisors not registered with the SEC. Real estate appraisers are covered because property appraisal is a listed financial activity, and career counselors who place people at financial organizations can also fall within the definition.2eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information
Not every individual who deals with a covered institution gets an annual notice. The rule draws a line between consumers and customers. A consumer is anyone who obtains a financial product or service for personal, family, or household purposes. A customer is a consumer with a continuing relationship: someone who holds a deposit account, carries a loan, or pays for ongoing financial advisory services. Only customers are entitled to the annual notice. A person who walks in once to buy a cashier’s check at a bank where they hold no account gets an initial notice at the time of the transaction, but no annual follow-up.3Consumer Financial Protection Bureau. CFPB Laws and Regulations GLBA Privacy
Licensed CPAs sit outside the annual notice rule when state professional conduct standards already prohibit them from disclosing nonpublic personal information without the consumer’s express consent. The carve-out is narrow and does not extend to a financial institution affiliated with the CPA.4GovInfo. 15 USC 6803 – Disclosure of Institution Privacy Policy
What the Notice Must Contain
The notice has to be clear, conspicuous, and an accurate description of what the institution actually does. Regulation P sets the required content:
- The categories of nonpublic personal information the institution collects, whether from the consumer, from transactions with the institution or its affiliates, from transactions with outside parties, or from consumer reporting agencies.
- The categories of nonpublic personal information the institution discloses.
- The categories of affiliates and outside parties who receive that information, illustrated with a few examples such as financial service providers, non-financial companies, or nonprofits.
- How the institution handles nonpublic personal information about former customers.
- The consumer’s right to opt out of disclosures to outside parties, together with the specific method for exercising it.
- The institution’s policies for protecting the confidentiality and security of nonpublic personal information.
The regulation lets institutions describe these items at the category level. You satisfy the collection requirement, for instance, by naming the source types rather than itemizing every data field.5Consumer Financial Protection Bureau. 12 CFR Part 1016 – Regulation P – Section 1016.6 Information to Be Included in Privacy Notices
The Model Privacy Form Safe Harbor
Federal regulators developed a model privacy form that, used correctly, counts as full compliance with the content rules under Regulation P.6eCFR. 12 CFR Part 1016 – Privacy of Consumer Financial Information (Regulation P) The form is optional, but it removes uncertainty over whether the format meets regulatory expectations.
The safe harbor has hard edges. Permitted modifications are limited to inserting the institution’s name, selecting the sharing categories that apply, using at least 10-point font, and adding a corporate logo that doesn’t interfere with readability. Adding extra content beyond what the instructions allow destroys the safe harbor. And the safe harbor doesn’t cover the accuracy of the answers on the form. Checking “No” for a category of sharing the institution actually engages in is a compliance failure the form won’t cure.7Federal Register. Final Model Privacy Form Under the Gramm-Leach-Bliley Act
When the Notice Has to Go Out
The first privacy notice must reach the customer no later than the time the customer relationship is established. After that, an annual notice must go out at least once in every period of twelve consecutive months for the life of the relationship.4GovInfo. 15 USC 6803 – Disclosure of Institution Privacy Policy The institution picks the twelve-month cycle, whether that’s the calendar year, its fiscal year, or the account anniversary, and must deliver consistently within it.
Separately, if the institution changes its privacy practices in a way that differs from the most recently delivered notice, a revised notice has to go out before the change takes effect. The revised notice sits alongside the annual notice cycle and can reset the annual clock.8Consumer Financial Protection Bureau. 12 CFR Part 1016 – Regulation P – Section 1016.5 Annual Privacy Notice to Customers Required
How the Notice Can Be Delivered
Delivery has to be reasonably understandable and designed to call attention to the information. Paper mail or in-person delivery satisfies that standard. The notice can’t be buried inside unrelated documents or set in type that discourages reading.9Federal Deposit Insurance Corporation. VIII-1 Gramm-Leach-Bliley Act (Privacy of Consumer Financial Information)
Electronic delivery is allowed with conditions. For customers who use the institution’s website to access their financial products or services, the institution can post the annual notice on the site if the customer has agreed to receive the notice electronically and the current notice is posted continuously in a clear and conspicuous manner. The notice must appear on a page the customer visits often, such as a transaction page, or be reachable through a clearly labeled link from one, and the page design cannot let graphics or hyperlinks pull attention away from the notice.6eCFR. 12 CFR Part 1016 – Privacy of Consumer Financial Information (Regulation P)
The Exception That Lets You Stop Sending It
Congress added the exception in December 2015 as part of the Fixing America’s Surface Transportation (FAST) Act. Titled “Eliminate Privacy Notice Confusion,” it added Section 503(f) to the GLBA and was implemented through amendments to Regulation P.10Federal Register. Amendment to the Annual Privacy Notice Requirement Under the Gramm-Leach-Bliley Act (Regulation P) The idea was to stop institutions from mailing identical notices year after year when nothing had changed and no opt-out right was in play.
Two conditions have to be met at the same time. First, the institution shares nonpublic personal information with outside parties only under exceptions that do not trigger the consumer’s opt-out right. Those exceptions cover sharing with service providers or joint marketing partners under a contract that limits how the information is used, sharing that is necessary to process or service a transaction the consumer requested, and certain other legally required or permitted disclosures. Any sharing that would normally require offering an opt-out breaks this condition.11eCFR. 12 CFR 1016.5 – Annual Privacy Notice to Customers Required
Second, the institution has not changed its disclosure policies and practices from what it told customers in the most recent privacy notice. The comparison is specific: current practices have to match the disclosures on categories of information shared, categories of recipients, and the other content items required under Regulation P.11eCFR. 12 CFR 1016.5 – Annual Privacy Notice to Customers Required
When both conditions hold, the institution can stop sending annual notices indefinitely. If it later loses eligibility and then re-qualifies, the exception picks back up.11eCFR. 12 CFR 1016.5 – Annual Privacy Notice to Customers Required
Losing the Exception: the 100-Day Rule
When either condition fails, the annual notice obligation snaps back. The timeline depends on whether the change also triggers a revised-notice requirement.
If the change requires a revised privacy notice under Regulation P (for example, beginning to share information with a new category of outside party), the revised notice must go out before the change is implemented. That revised notice then resets the annual clock as if it were a new initial notice. An institution whose twelve-month cycle runs on the calendar year and sends the revised notice on March 1 of year one owes its next annual notice by December 31 of year two.8Consumer Financial Protection Bureau. 12 CFR Part 1016 – Regulation P – Section 1016.5 Annual Privacy Notice to Customers Required
If the change disqualifies the institution from the exception but doesn’t rise to the level of triggering a revised notice, the institution has to deliver an annual privacy notice within 100 days of the change.8Consumer Financial Protection Bureau. 12 CFR Part 1016 – Regulation P – Section 1016.5 Annual Privacy Notice to Customers Required This is the deadline that catches compliance teams off guard. A relatively minor operational shift, like beginning to share data with a joint marketing partner in a way that technically falls outside the permitted exceptions, can start a 100-day countdown the institution may not immediately recognize.
Who Enforces the Rule
No single agency enforces the GLBA privacy rules across every covered institution. Enforcement is split among the federal functional regulators, each covering the institutions already under its jurisdiction. The Office of the Comptroller of the Currency handles national banks. The Federal Reserve Board covers state-chartered member banks and bank holding companies. The FDIC oversees state-chartered banks that are not Federal Reserve members. The National Credit Union Administration handles federally insured credit unions. The SEC covers broker-dealers, investment companies, and registered investment advisors. State insurance authorities regulate insurance providers.12Federal Trade Commission. How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act
The FTC picks up any financial institution not supervised by another federal agency, which puts many of the nontraditional players (tax preparers, collection agencies, mortgage brokers not affiliated with a bank) under its jurisdiction.12Federal Trade Commission. How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act Penalties depend on which agency has jurisdiction and the enforcement tools available under its statute. Banking regulators can pursue cease-and-desist orders and civil money penalties under the Federal Deposit Insurance Act; the FTC can seek injunctive relief and civil penalties under the FTC Act.