Gramm-Leach-Bliley Act, Title V
Tier 1 In forceThe financial-sector rules, and the clearest example in the Atlas of a genuine multi-regulator split within one country. Two features catch people out: "financial institution" is far broader than banks, reaching mortgage brokers, tax preparers, car dealers and higher-education institutions; and sharing with non-affiliated third parties is opt-OUT rather than opt-in, with wide exceptions.
Identity
- Citation
- Pub. L. 106-102, Title V; Regulation P, 12 CFR Part 1016; FTC Safeguards Rule, 16 CFR Part 314
- Jurisdiction
- United States
- Type
- sectoral
Amended by: The Safeguards Rule breach-notification requirement took effect on 13 May 2024: notify the FTC as soon as possible and no later than 30 days, where at least 500 consumers are affected.
Asymmetry checklist
All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap. Checked by Fable on 26 July 2026.
| # | Point | Finding | Notes |
|---|---|---|---|
| 1 | Territorial extent | Asymmetry found | The Act and its rules apply uniformly nationwide with no regional carve-out, but GLBA sets a floor rather than a ceiling: state law affording greater protection is preserved. The practical consequence is that the operative standard varies by state, most visibly where a state has substituted an opt-in requirement for GLBA's federal opt-out default for sharing with non-affiliated third parties. |
| 2 | Commencement | None found — checked | None found — checked. Title V and the Privacy Rule have been in force since the 2000-2001 implementation, and the later amendments have all taken effect: the 2021 Safeguards Rule amendments and the notification requirement that became effective on 2024-05-13. As at 2026-07-26 no provision identified in this pass remains phased or pending. |
| 3 | Sunset / mandatory review | None found — checked | None found — checked. Neither Title V nor the implementing rules contain an expiry, lapse or mandatory periodic review provision. |
| 4 | Criminal liability | Asymmetry found | A distinct criminal track exists and is separate from the civil supervisory regime: the pretexting provisions in Title V Subtitle B criminalise obtaining or attempting to obtain customer information of a financial institution by false, fictitious or fraudulent statements, or by forged or counterfeit documents. Custody is available, with an enhanced penalty where the offence is committed while violating another federal law or as part of a pattern of illegal activity involving more than USD 100,000 in a twelve-month period. Enforcement is by the Department of Justice, not by the supervisory agencies. NOTE: the pretexting provisions were not covered in the verified pass of 2026-07-26 — see the sheet; confirm the section numbers and current maxima before promotion. |
| 5 | Civil liability | None found — checked | None found — checked. GLBA creates no general private right of action for breach of the privacy or safeguards obligations; enforcement is by the relevant federal or state supervisory agency. Individuals affected by a failure typically proceed under state consumer-protection statutes, negligence, or contract, with GLBA sometimes invoked as a standard of care. |
| 6 | Regulatory enforcement toolkit | Asymmetry found | This is a genuine multi-regulator split rather than a single enforcer with a single ceiling, and it is the field most often flattened in summaries. Rulemaking for the Privacy Rule (Regulation P, 12 CFR Part 1016) sits with the CFPB; the FTC administers and enforces the Safeguards Rule (16 CFR Part 314) against non-bank financial institutions; the federal prudential banking regulators supervise their own institutions; and the SEC and state insurance regulators cover their respective sectors. Which agency can act, and with what tools, depends on what kind of institution the respondent is. Since 2024-05-13 the Safeguards Rule also requires notification to the FTC as soon as possible and no later than 30 days after discovery of an event involving the unencrypted information of 500 or more consumers. |
| 7 | Personal / director liability | Asymmetry found | The pretexting offences attach to the natural person who obtains or attempts to obtain the information, so individuals — including employees of information brokers and third-party investigators — face personal criminal exposure independently of any action against an institution. Institution-level civil enforcement, by contrast, runs against the entity. |
| 8 | Public vs private sector split | Asymmetry found | GLBA binds "financial institutions", a term far broader than banks and routinely underestimated: the FTC has applied it to mortgage brokers, tax preparers, motor vehicle dealers, debt collectors and higher-education institutions administering federal student aid. The split is compounded by the regulator allocation, since the same substantive obligation is supervised by different agencies depending on the entity type. Entities outside the definition are unaffected regardless of how much financial data they hold. |
| 9 | Legal-person coverage | None found — checked | None found — checked. The regime protects "consumers" and "customers", defined as individuals obtaining financial products or services primarily for personal, family or household purposes. Information about business customers and commercial accounts falls outside the privacy provisions entirely. |
| 10 | Exemptions — with conditions | Asymmetry found | The shape of the regime is an opt-out default riddled with exceptions that substantially narrow it. Notice and opt-out are required before sharing non-public personal information with non-affiliated third parties, but sharing is permitted without opt-out where it falls within the service provider and joint marketing exception (subject to a contractual confidentiality undertaking), or within the processing and servicing exceptions covering transactions the consumer requested, fraud prevention, legal compliance and similar purposes. Sharing with AFFILIATES is largely outside the opt-out altogether. Reciting "consumers can opt out" without these exceptions materially overstates the control the Act confers. |
Civil liability
None found — checked. No general private right of action.
Regulatory enforcement
Which regulator applies depends on what kind of institution you are — there is no single supervisory authority, and the answer changes the applicable rules and examination regime.
Legal-person coverage
- Covers legal persons
- No — natural persons only
Protects consumers and customers as natural persons.
Public / private sector split
- Separate regimes
- Yes
Sectoral and regulator-split simultaneously. The obligations are broadly common but supervision is divided by institution type across four sets of regulators.
Interactions and conflicts
The CCPA carves out GLBA-regulated data at data level rather than exempting the institution, so a financial institution can be inside both regimes for different datasets simultaneously.
Live issues
Sources
- Primary Gramm-Leach-Bliley Act, Title V US Government Publishing Office no verified URL yet
URL unconfirmed.
- Primary FTC Safeguards Rule, 16 CFR Part 314 Federal Trade Commission no verified URL yet
URL unconfirmed.
Never independently verified — seeded from the prototype.