Your Privacy Rights
GLBA and Your Financial Data: The Privacy Law Gap
The short version
The Gramm-Leach-Bliley Act regulates how financial institutions handle your data - and because it already regulates them, nearly every state privacy law written since has carved that data back out. Your deletion request, your do-not-sell request, and California's DROP platform all stop at the edge of it. GLBA itself gives you a notice and a narrow opt-out, not a delete button. What still works is the Fair Credit Reporting Act: free reports, free freezes, prescreen opt-outs, and disputes. This post maps the gap and the rights that survive it.
What the Gramm-Leach-Bliley Act actually does
GLBA is a 1999 federal law, Public Law 106-102, that governs how financial institutions handle customer information. The FTC describes it as requiring companies that offer consumers financial products or services "to explain their information-sharing practices to their customers and to safeguard sensitive data." It is a disclosure and security law, not a data-minimisation one.
Two rules do the work. The Privacy Rule, implemented for most non-bank institutions as Regulation P, controls notices and sharing. The Safeguards Rule is the security side: the FTC says it "requires covered companies to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards designed to protect customer information."
"Financial institution" is broader than it sounds. It reaches lenders, mortgage brokers, insurers, investment advisers, tax preparers, debt collectors and car dealers that arrange financing - not just banks.
What counts as nonpublic personal information
GLBA protects "nonpublic personal information", or NPI. The FTC's compliance guide splits it into three buckets: what you give an institution to obtain a financial product or service, what your use of that service generates, and related information the institution obtains from third parties. That covers a great deal of your financial life.
The important exclusion is at the other end. NPI "does not include information that you have a reasonable basis to believe is lawfully made 'publicly available'", such as a recorded mortgage or a widely distributed directory. So the deed filed when you bought your house is outside GLBA's protection - and it is exactly the record people-search and property brokers ingest.
The one right GLBA gives you, and its exceptions
The consumer right in GLBA is narrow: notice, plus the ability to opt out before your institution discloses your NPI to nonaffiliated third parties. The FTC's guide is clear that customers must get notice "and have a reasonable opportunity to opt out...before you can disclose their NPI". That is the whole of it.
Then come the exceptions, and they are wide. The FTC compliance guide describes three that remove the opt-out entirely:
- Processing your transaction - disclosures necessary for processing or administering a financial transaction you requested or authorised.
- Legal and fraud purposes - preventing fraud, responding to judicial process, or complying with federal, state or local law.
- Service providers and joint marketing - sharing under a written contract that bars the recipient from using the data for any other purpose.
The third is the one people find surprising: a joint marketing arrangement can move your data to another company without an opt-out, provided the contract is in place.
How the carve-out swallows state privacy law
Here is the mechanism that matters. State privacy laws generally decline to regulate what GLBA already regulates, and they do it in two different styles. California removes the data. Virginia removes the company. The second is much broader in practice.
California's Civil Code section 1798.145(e) exempts "personal information collected, processed, sold, or disclosed subject to the federal Gramm-Leach-Bliley Act (Public Law 106-102), and implementing regulations, or the California Financial Information Privacy Act". Virginia's Consumer Data Protection Act, at section 59.1-576(B), instead exempts a "financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act".
The difference is real. Under the Californian style, a company that holds both GLBA data and ordinary marketing data still owes you rights over the marketing half. Under the Virginia style, an entity that qualifies as a financial institution can be out of scope altogether, whatever else it holds.
Why California's DROP will not clear these records
California's Delete Act platform, DROP, is the strongest deletion tool any US consumer has: one free request that reaches over 500 registered data brokers, with brokers required to process requests from August 1, 2026. It is genuinely worth using. It will not touch your financial file.
DROP does not cover data falling under the FCRA, GLBA or HIPAA exemptions, nor companies you have a direct relationship with, nor search engines and social media. So your credit file, mortgage servicing history and bank records are outside it by design. Our Delete Act explainer covers what it does reach.
This is the single most common misunderstanding we see: people file a DROP request, see their financial data untouched months later, and conclude the platform is broken. It is not broken. It was never pointed at that data.
What GLBA does not give you
GLBA has no deletion right. It has no correction right. It has no data-portability right, no right to a copy of everything held about you, and no private right of action for a consumer to sue over a privacy-notice failure. Compared to a modern state privacy law, it is a thin instrument.
That gap is why a "delete my data" email to a lender rarely produces the result people expect. The institution is not stonewalling you - in most states it has no obligation to delete regulated financial data at all, and often has retention obligations pointing the other way.
If a company simply ignores a request you are entitled to make, that is a different problem with different remedies. We wrote about it in what to do when a company ignores your deletion request.
Why the annual privacy notice stopped arriving
If you noticed those dense annual privacy leaflets thinning out, that was a deliberate change in the law rather than institutions cutting corners. Congress amended GLBA in the FAST Act, enacted December 4, 2015, adding section 503(f) - titled "Eliminate Privacy Notice Confusion" - which creates an exception to the annual notice requirement.
An institution qualifies if it shares NPI only within the statutory exceptions and has not changed the policies described in its most recent notice. The CFPB's matching amendments to Regulation P took effect September 17, 2018. The practical result: no notice can now mean "nothing changed" rather than "nothing to disclose", so the absence of a leaflet tells you very little.
What you can still act on, and under which law
Almost every practical control over financial data comes from the Fair Credit Reporting Act, not GLBA. That is the mental switch worth making: stop asking what a privacy law lets you delete, and start using the credit-reporting rights that already exist. All of the following are free.
| What you can do | Law behind it | Cost | How often or how long |
|---|---|---|---|
| Get your report from each nationwide bureau | FCRA | Free | Weekly, at AnnualCreditReport.com |
| Place or lift a security freeze | FCRA | Free | Lasts until you lift it |
| Opt out of prescreened credit and insurance offers | FCRA | Free | 5 years online or by phone; permanent by signed form |
| Get your file from a specialty reporting company | FCRA | Free | Once every 12 months |
| Opt out of affiliate marketing use | FCRA section 624 | Free | At least 5 years, then a renewal notice |
| Opt out of sharing with nonaffiliated third parties | GLBA | Free | Indefinite, but three exceptions apply |
Compiled from FTC consumer guidance on free credit reports, credit freezes and prescreened offers, the FTC Affiliate Marketing Rule, the FTC GLBA Privacy Rule compliance guide, and CFPB guidance on consumer reporting companies.
On the free reports: the FTC states that "all three nationwide credit bureaus have permanently extended a program that lets you check your credit report from each once a week for free at AnnualCreditReport.com." On freezes, it says plainly that "there's no cost to place or lift a credit freeze" and to contact all three bureaus.
The prescreen opt-out is the highest-value single action, because it runs jointly across the bureaus. The FTC says requests are processed within five days, though offers can keep arriving for weeks. Our Experian opt-out guide walks the steps, and our post on prescreened offers covers the five-year versus permanent choice.
Beyond the three big bureaus sit dozens of specialty consumer reporting companies covering tenancy, employment screening, check-writing, insurance claims and medical payments. The CFPB publishes a list of them precisely so consumers can request their data, dispute inaccuracies and place freezes. Most provide a report free every 12 months.
These files matter more than their obscurity suggests, because a tenant-screening or check-writing record can cost you an apartment or a bank account without ever appearing on a credit report. Our credit and risk opt-out category collects the ones worth working through, and our FCRA background-check post explains your dispute rights when a report is wrong.
The property case: CoreLogic, now Cotality
Property data shows the carve-out at its most frustrating. CoreLogic rebranded to Cotality in 2025, and its product privacy policy states that it does not apply to information regulated by the Gramm-Leach-Bliley Act or the Fair Credit Reporting Act. Much of what the company holds on mortgages, tenancy and property is exactly that.
So a successful privacy request there suppresses the marketing layer and leaves the regulated layer intact. Any guide promising a clean sweep of that company is overstating what the request does. Our CoreLogic and Cotality guide documents the live request routes, including the rebrand that broke the old opt-out URL cited across the internet.
The route that does work on regulated property and tenancy data is the FCRA one: request the file, read it, and dispute what is wrong.
Where federal rulemaking stands
There was a serious federal attempt to close part of this gap, and it did not land. The CFPB published a proposed rule, "Protecting Americans from Harmful Data Broker Practices (Regulation V)", on December 13, 2024, which would have treated more data brokers as consumer reporting agencies and limited the sale of identifiers such as Social Security numbers.
The Bureau withdrew it on May 15, 2025, saying commenters had raised concerns - including about the Bureau's statutory authority - that made proceeding to a final rule inappropriate. Nothing replaced it. Plan around the law as it stands, not the rule that was proposed.
One thing did change on the security side. Since May 13, 2024, non-banking financial institutions under the Safeguards Rule must notify the FTC no later than 30 days after discovering a breach involving the unencrypted information of at least 500 consumers. That produces public notice of incidents you would previously never have heard about.
A practical order of operations
If you take one thing from the carve-out, make it this: spend your effort where the rights are real. Deletion requests aimed at regulated financial data mostly return polite refusals, while the FCRA route reliably produces documents you can act on. A sensible sequence takes an afternoon.
- Pull your three bureau reports at AnnualCreditReport.com and read the address and account history, not just the score.
- Freeze all three files. It is free and it blocks the harm the data enables.
- Do the joint prescreen opt-out once, and choose permanent if you are willing to return the signed form.
- Request your files from the specialty companies that apply to you - tenancy, employment screening, check-writing.
- Dispute anything inaccurate in writing, and keep the dated record.
- Then work the non-financial side: the people-search sites, where deletion rights genuinely apply.
That last step is where a state deletion request or DROP earns its keep, and where most of your publicly searchable exposure actually lives.
See what is exposed outside the carve-out
The people-search side of your footprint is the part you can actually get removed. Run a free exposure scan to see which brokers likely list you, plus any breaches tied to your email - no account, nothing stored.
Frequently asked questions
Does the Gramm-Leach-Bliley Act let me delete my financial data?
No. The consumer right GLBA creates is a privacy notice plus an opt-out from your financial institution sharing your nonpublic personal information with nonaffiliated third parties. There is no deletion right in the statute, and no correction right either. Correction of credit-report data comes from the Fair Credit Reporting Act instead.
What is the GLBA exemption in state privacy laws?
Most US state privacy laws exclude financial data that GLBA already regulates, so a state deletion or do-not-sell request does not reach it. California exempts the data: Civil Code section 1798.145(e) covers personal information collected, processed, sold, or disclosed subject to GLBA. Virginia goes further and exempts the whole company, using the phrase financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act.
Will California's DROP platform remove my credit or mortgage records?
No. DROP sends one deletion request to every registered California data broker, but it does not reach data covered by the FCRA, GLBA or HIPAA exemptions. Your credit file, mortgage servicing records and bank account history sit outside it. DROP is still worth using for the people-search side of your footprint.
What counts as nonpublic personal information under GLBA?
Information you give a financial institution to get a product or service, data generated by using that service, and related information the institution gets from third parties. The FTC's compliance guide is explicit that it does not include information the institution has a reasonable basis to believe is lawfully made publicly available, such as a recorded mortgage.
Can I stop my bank sharing my data with its affiliates?
Partly, and the right comes from the FCRA rather than GLBA. The Affiliate Marketing Rule implements section 214 of the FACT Act and generally bars a company from using information received from an affiliate to market to you unless you were given notice and a simple way to opt out. That election lasts at least five years, after which you get a renewal notice.
Why did my bank stop sending an annual privacy notice?
Congress changed the rule. The FAST Act, enacted December 4, 2015, added GLBA section 503(f), which excuses an institution from the annual notice if it shares nonpublic personal information only within the statutory exceptions and has not changed the policies described in its last notice. The CFPB's matching Regulation P amendments took effect September 17, 2018.
Is a credit freeze free, and does it cover the GLBA gap?
The FTC states there is no cost to place or lift a credit freeze, and advises contacting all three nationwide bureaus: Equifax, Experian and TransUnion. It does not delete anything, so it does not close the GLBA gap. What it does is block new credit being opened in your name, which is the harm the underlying data enables.
Did the CFPB ever regulate data brokers under the FCRA?
It tried and stopped. The Bureau published a proposed rule, Protecting Americans from Harmful Data Broker Practices (Regulation V), on December 13, 2024, and withdrew it on May 15, 2025, saying commenters had raised concerns about its statutory authority that made proceeding to a final rule inappropriate.
Sources: FTC business guidance on the Gramm-Leach-Bliley Act and the Safeguards Rule; the FTC's "How To Comply with the Privacy of Consumer Financial Information Rule"; FTC consumer advice on free credit reports, credit freezes and prescreened offers; the FTC Affiliate Marketing Rule; California Civil Code section 1798.145(e); Virginia Code section 59.1-576(B); CFPB guidance on Regulation P annual notices and on consumer reporting companies; the Federal Register withdrawal of Protecting Americans from Harmful Data Broker Practices (Regulation V), May 15, 2025; Cotality's product privacy policy; and the California Privacy Protection Agency on the Delete Act and DROP.