GlossarySecurity & compliance

GLBA

GLBA (the Gramm-Leach-Bliley Act) is the federal law requiring financial institutions to explain how they share customers' nonpublic personal information and to protect that information with a security program.

  • Security & compliance
  • Updated
  • Written by the Telxpress advisory team

01 In depth

What it is, why it matters and what to ask a vendor

GLBA has two parts that matter day to day. The Privacy Rule requires clear notices about information sharing and an opt-out for certain disclosures. The Safeguards Rule requires an information security program with administrative, technical and physical safeguards. Banks are supervised by their banking regulators; the FTC covers non-bank institutions such as dealers, lenders and advisors.

For a growing financial firm the law follows the customer data into every system: the CRM, the phone recordings, the video meetings with clients and the vendors behind them. Adding an AI agent that answers client calls means adding a service provider who must be vetted and bound by contract.

Ask vendors how they protect nonpublic personal information at rest and in transit, who can access it, how they support your vendor-oversight duties and whether they will sign safeguards terms. Ask your compliance officer which regulator supervises you, because the detailed expectations differ. This entry is a definition, not legal advice.

03 At Telxpress

Where this shows up at Telxpress

The pages and articles where this term does real work: what we advise, build and support.

04 Sources

Public references

The standard or law this definition rests on, as published by its owner. Fetched and checked on the review date above.

Next step

Want This Applied to Your Business?

Book a free 30-minute AI readiness consultation. You'll leave with three AI opportunities specific to your business, whether you work with us or not.

Or call 24/7: (949) 861-4500

Last reviewed: . Published by Telxpress, Irvine, CA.