15 U.S.C. §§ 6801-6809

Gramm-Leach-Bliley Act

Statute — United States Federal
Effective: November 12, 1999 53 platforms tracked 999 provisions indexed Enforced by: Federal Trade Commission (FTC), Consumer Financial Protection Bureau (CFPB), Federal Banking Regulators (OCC, FDIC, Federal Reserve) Last reviewed May 9, 2026

Overview

The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data. The Act has three principal components relevant to platform governance: the Financial Privacy Rule, the Safeguards Rule, and pretexting protections.

The Financial Privacy Rule requires financial institutions to provide customers with privacy notices explaining what information is collected, where it is shared, how it is used, and how it is protected. Customers must receive these notices when they first establish a relationship and annually thereafter.

The Safeguards Rule, updated significantly by the FTC in 2023, requires financial institutions to develop, implement, and maintain a comprehensive information security program including risk assessments, access controls, encryption, multi-factor authentication, and incident response plans.

Penalties

Criminal penalties for pretexting: fines up to $100,000 for individuals, $500,000 for institutions, and up to 5 years imprisonment.

Key Articles & Sections

Platforms We Track Subject to GLBA

Recent Changes Related to GLBA

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by GLBA (999 across 53 platforms)

Behavioral Analytics and Tracking Technologies Acorns
Medium
Account Suspension and Termination Acorns
Medium
Account Linking and Third-Party Data Aggregator Access Acorns
Medium
California Resident Privacy Rights (CCPA) Acorns
Medium
Collection of Sensitive Financial and Identity Data Acorns
Medium
Incorporation by Reference of Product-Specific Agreements Acorns
Medium
California Consumer Privacy Act Rights Acorns
Medium
Children's Data and Acorns Early Product Acorns
Medium
Business Transfer Data Disclosure Acorns
Medium
Custodial Account Terms — Minors (Acorns Early) Acorns
Medium
California Consumer Privacy Rights Acorns
Medium
Device, Behavioral, and Geolocation Data Collection Acorns
Medium
Data Retention and Deletion Rights Acorns
Medium
Security of Personal Information Acorns
Medium
Geolocation and Device Data Collection Acorns
Medium
California Resident Privacy Rights Acorns
Medium
Data Collection from Third-Party Sources Including Data Brokers Acorns
Medium
Data Sharing with Affiliates and Service Providers Acorns
Medium
Data Sharing with Fraud Prevention Networks and Government Authorities Adyen
Medium
Data Retention Periods Adyen
Medium
California Consumer Rights (CCPA/CPRA) Adyen
Medium
Dual Controller and Processor Role Adyen
Medium
Data Processing and Sharing with Card Schemes Adyen
Medium
Third-Party Data Sharing Adyen
Medium
Card Scheme Rule Incorporation Adyen
Medium
Cross-Border Data Transfers Adyen
Medium
Acceptable Use Policy Compliance Obligation Adyen
Medium
Legitimate Interests as Processing Basis Adyen
Medium
KYC Identity Data Collection and Retention Adyen
Medium
Cookie and Behavioral Tracking Adyen
Medium

Showing 30 of 999 provisions. View all →

Related Regulations

Official Source

View official regulation text →

Get alerted when platforms change their policies — including GLBA-relevant provisions.

Subscribe to Monitor — $19/mo

Frequently Asked Questions

What does GLBA require?

Which platforms does GLBA apply to?

ConductAtlas tracks GLBA-relevant provisions across 53 platforms. Each platform's specific provisions are classified by severity and mapped to GLBA requirements.

How does ConductAtlas monitor GLBA compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect GLBA obligations. Every change is archived with cryptographic verification.