---
title: GLBA Compliance Requirements - SCA Security
description: The Gramm-Leach-Bliley Act which is also known as the Financial Modernization ACT OF 1999, is a United States federal law that requires all financial institutions to ensure the privacy and security of customer (non-public) information. The Act consists of three sections. The Privacy Rule that regulates the gathering and disclosure of private information. The Safeguards
image: https://blog.scasecurity.com/hubfs/Imported_Blog_Media/GLBA-Compliance-Requirements.png
---

[727-571-1141 Talk to an Expert](tel:727-571-1141) [info@scasecurity.com Email Us](mailto:info@scasecurity.com) <https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs> <https://twitter.com/scasecurity> <https://www.linkedin.com/company/security-compliance-associates/>

[![sca-logo-r](https://blog.scasecurity.com/hs-fs/hubfs/sca-logo-r.png?length=190&name=sca-logo-r.png)](https://scasecurity.com/)

☰

- [Home](https://scasecurity.com/)
- [Security](https://scasecurity.com/security/) 
    - [Email Phishing & Employee Training](https://scasecurity.com/anti-phishing-training-with-phished-io/)
    - [Vulnerability Assessments](https://scasecurity.com/security/vulnerability-assessments/)
    - [Penetration Testing](https://scasecurity.com/security/penetration-testing/)
    - [Applications](https://scasecurity.com/security/applications/)
    - [Controls](https://scasecurity.com/security/controls/)
    - [Centurion ESO](https://scasecurity.com/executive-security-officer/)
    - [Consulting](https://scasecurity.com/security/consulting/)
- [Risk & Compliance](https://scasecurity.com/compliance/) 
    - [CMMC](https://scasecurity.com/cybersecurity-maturity-model-certification/)
    - [HITRUST](https://scasecurity.com/hitrust/)
    - [Federal](https://scasecurity.com/compliance/federal/)
    - [State](https://scasecurity.com/compliance/state/)
    - [Industry](https://scasecurity.com/compliance/industry/)
    - [Cybersecurity Risk Assessment](https://scasecurity.com/security/risk-assessment/)
    - [NIST Cybersecurity Framework Assessment](https://scasecurity.com/compliance/nist-framework/)
    - [AI Risk Management Services](https://scasecurity.com/ai-risk-management-services/)
- [Governance](https://scasecurity.com/compliance/governance/)
- [Industries](https://scasecurity.com/industries/) 
    - [Financial Services](https://scasecurity.com/industries/financial-services/)
    - [Healthcare](https://scasecurity.com/industries/healthcare/)
    - [Government/Public Sector](https://scasecurity.com/industries/government-public-sector/)
    - [Title/Real Estate](https://scasecurity.com/industries/title-real-estate/)
    - [Technology](https://scasecurity.com/industries/technology/)
    - [Manufacturing](https://scasecurity.com/industries/manufacturing/)
    - [Professional Services](https://scasecurity.com/industries/professional-services/)
    - [Automotive](https://scasecurity.com/automotive/)
    - [Higher Education](https://scasecurity.com/higher-education/)
- News & Resources 
    - [Blog](https://blog.scasecurity.com)
    - [Events](https://scasecurity.com/event/)
    - [Case Studies](https://scasecurity.com/case-studies/)
    - [Recorded Webinars](https://scasecurity.com/recorded-webinars/)
    - [SCA Breach Notification Guide](https://scasecurity.com/breach-notification-guide/)
    - [HIPAA Security Audit Checklist](https://info.scasecurity.com/hipaa-audit-checklist)
    - [Cybersecurity Checklist for Insurance Providers](https://info.scasecurity.com/cybersecurity-checklist-for-insurance-providers)
- Company 
    - [About Us](https://scasecurity.com/about-us/)
    - [Leadership](https://scasecurity.com/leadership/)
    - [Affiliates](https://scasecurity.com/affiliates/)
    - [Career Opportunities](https://scasecurity.com/career-opportunities/)
    - [Testimonials](https://scasecurity.com/testimonials/)
- [Contact Us](https://scasecurity.com/contact-us/)

#### Menu

 Home

 Security ›

 Email Phishing & Employee Training

 Vulnerability Assessments

 Penetration Testing

 Applications

 Controls

 Centurion ESO

 Consulting

 Risk & Compliance ›

 CMMC

 HITRUST

 Federal

 State

 Industry

 Cybersecurity Risk Assessment

 NIST Cybersecurity Framework Assessment

 AI Risk Management Services

 Governance

 Industries ›

 Financial Services

 Healthcare

 Government/Public Sector

 Title/Real Estate

 Technology

 Manufacturing

 Professional Services

 Automotive

 Higher Education

 News & Resources ›

 Blog

 Events

 Case Studies

 Recorded Webinars

 SCA Breach Notification Guide

 HIPAA Security Audit Checklist

 Cybersecurity Checklist for Insurance Providers

 Company ›

 About Us

 Leadership

 Affiliates

 Career Opportunities

 Testimonials

 Contact Us

[727-571-1141 Talk to an Expert](tel:727-571-1141)

[info@scasecurity.com Email Us](mailto:info@scasecurity.com)

<https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs>

<https://twitter.com/scasecurity>

<https://www.linkedin.com/company/security-compliance-associates/>

 November 20, 2018

# GLBA Compliance Requirements

 By: SCA Editor

![](https://blog.scasecurity.com/hubfs/Imported_Blog_Media/GLBA-Compliance-Requirements.png)

The Gramm-Leach-Bliley Act which is also known as the Financial Modernization ACT OF 1999, is a United States federal law that requires all financial institutions to ensure the privacy and security of customer (non-public) information. The Act consists of three sections.

1. **The Privacy Rule** that regulates the gathering and disclosure of private information.
2. **The Safeguards Rule** which specifies that financial institutions must implement safety programs to safeguard such information. This safeguard also applies to ATM operators and companies like credit reporting agencies that collect private information of individuals from financial institutions.
3. **The Pretexting Provisions** that prohibits the practice of obtaining private information and using it under false pretenses.

### Who is covered by this Act?

The term ‘financial institution’ includes many organizations that describe themselves as financial institutions. These institutions include banks, credit unions, payday lenders, mortgage brokers, personal property or real estate appraisers, non-bank lenders among others. If your business deals with loans, the collection of debts, and financial advice, the GLBA applies to you as a financial institution. The law applies to all financial institutions regardless of the size. The Federal Trade Commission (FTC), as well as other government agencies, order financial institutions to implement regulations to meet the GLBA compliance requirements.

### What are the GLBA Compliance Requirements?

As part of your GLBA compliance requirement, you are required to meet the three sections of the Act. These sections include The Financial Rule, The Safeguards Rule, and The Pretexting Provisions.

● The Privacy Rule is the first piece in your GLBA compliance requirements. It mandates that you provide proper notices of your privacy policies and practices to the individuals who are using your products or services. If an institution intends to disclose a client’s private information, it must provide the client with a privacy notice. This notice offers the clients the choice to opt in or out if they choose not to share their personal data with third parties.

● The Safeguards Rule requires financial institutions to keep customer information secure. They are also required to ensure that affiliates or 3rd party service providers also take steps to secure customer information. Often mentioned together with information and cybersecurity the Safeguards Rule requires you to perform a comprehensive risk assessment and design, implement and maintain a detailed information [security](https://scasecurity.com/security/) program to protect customers’ private information in all areas of operation.

● The Pretexting Provisions section also involves cybersecurity. To comply with this rule, a written plan must be developed for monitoring account activities as well as educating your employees to recognize social engineering and phishing cons.

According to the Federal Trade Commission, the GLBA requirements are made flexible to enable every institution to implement an information security plan that is reasonable and makes sense with the scope and the activities of the company. Enforcement of the GLBA is performed through the member agencies of the Federal Financial Institutions Examination Council (FFIEC) which include the Board of Governors of the Federal Reserve System (FRB), Federal Deposit Insurance Corporation (FDIC), National Credit Union Association (NCUA), Office of the Comptroller of the Currency (OCC) and the Consumer Financial Protection Bureau (CFPB). GLBA also requires an incident response and disaster recovery plans to prepare for and respond to beaches and natural and man-made disasters. Maintaining GLBA compliance is significant to financial institutions as it helps them secure and defend their network while reducing reputation, regulatory and legal risks that can be both expensive and detrimental to continued operations.

### Contact SCA Today to Learn More About GLBA Compliance Requirements

Security [Compliance](https://scasecurity.com/compliance/) Associates (SCA) has more than 13 years of practice in delivering topnotch [financial security compliance](https://scasecurity.com/industries/financial-services/), Assessment, and Advisory services to financial institutions throughout the United States. Our assessments include a thorough review of your existing information security posture; the people, process and technology that may compromise sensitive information. SCA employs credentialed analysts and compliance professionals with decades of combined information security experience and will tailor an assessment program unique to your institution’s needs, size and culture.

Contact SCA today to schedule a no-cost consultation.

#### Subscribe

Email\*

Notification Frequency

[Blog](https://blog.scasecurity.com/tag/blog)

[February 07, 2025 Preparing for 2025 HIPAA Changes: What Healthcare Organizations Need to Know](https://blog.scasecurity.com/preparing-for-2025-hipaa-changes-what-healthcare-organizations-need-to-know) [October 23, 2024 What is a Vulnerability Assessment (and Why You Need One)](https://blog.scasecurity.com/blog/what-is-a-vulnerability-assessment) [October 10, 2024 Understanding the Risks and Mitigation of Phishing Attacks](https://blog.scasecurity.com/understanding-the-risks-and-mitigation-of-phishing-attacks)

### Comments

© 2026 - All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SCA Editor",
    "url" : "https://blog.scasecurity.com/author/sca-editor"
  },
  "dateModified" : "2025-04-10T16:06:13.538Z",
  "datePublished" : "2018-11-20T05:00:00.000Z",
  "headline" : "GLBA Compliance Requirements - SCA Security",
  "image" : [ "https://blog.scasecurity.com/hubfs/Imported_Blog_Media/GLBA-Compliance-Requirements.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.scasecurity.com/glba-compliance-requirements",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.scasecurity.com/hubfs/sca-logo-r.png"
    },
    "name" : "Security Compliance Associates"
  }
}
```