★★★★★ 4.9 / 5 87 reviews Tewksbury, MA · Since 2007
AA+ Rated HIPAA FACTA
Compliance Resource

What Is the Gramm-Leach-Bliley Act?

Plain-English guide to GLBA for Massachusetts financial businesses. Who is covered, what disposal rules apply, the real penalties and how to comply without overhauling your operations.

By Erica McKowski · Published November 2024 · Updated May 2026

The Gramm-Leach-Bliley Act, often shortened to GLBA, is the federal law that requires “financial institutions” to safeguard consumer financial information. Most Massachusetts business owners hear “financial institution” and assume the law applies only to banks. The reality is much broader. If your business handles consumer credit data, account information or similar financial details, GLBA likely applies to you, including your disposal practices.

This guide walks through who GLBA covers, what the law requires, what enforcement actually looks like and the practical disposal practices that satisfy compliance for metro Boston businesses.

Who GLBA Covers

The Federal Trade Commission’s GLBA Safeguards Rule defines “financial institution” as any business “significantly engaged in financial activities.” That definition is intentionally wide. The most commonly covered metro Boston businesses include:

  • Banks, credit unions and savings institutions
  • Tax preparers and CPA firms
  • Mortgage brokers and mortgage lenders
  • Real estate brokerages handling closings or financing referrals
  • Auto dealers offering financing
  • Investment advisers and broker-dealers
  • Financial planners and wealth managers
  • Check cashers, payday lenders and money transmitters
  • Insurance agencies handling annuities, mortgage insurance or similar products
  • Consumer reporting agencies (credit bureaus) and resellers
  • Debt collectors and credit counseling services

If your business collects, processes or stores consumer financial information from someone you have a customer relationship with, GLBA likely applies. The threshold is whether you have customers with non-public personal information (NPI) on file. Email addresses and contact info alone do not trigger GLBA. Account numbers, Social Security numbers, financial transaction history or credit information do.

What GLBA Requires

GLBA has three primary rules: the Privacy Rule, the Safeguards Rule and the Pretexting Rule. For most metro Boston businesses, the Safeguards Rule is where compliance work concentrates.

The Safeguards Rule

The Safeguards Rule requires every covered business to develop, implement and maintain a written information security program (WISP). The WISP must include:

  • A designated qualified individual responsible for the program
  • A written risk assessment identifying foreseeable threats to customer information
  • Safeguards designed to control the identified risks, including access controls, encryption, multi-factor authentication and disposal practices
  • Service provider oversight, with contracts requiring those providers to maintain comparable safeguards
  • Regular monitoring, testing and training
  • An incident response plan
  • Written annual reporting to the board or senior leadership

Disposal of customer information is explicitly identified as one of the required safeguards. The FTC has issued specific guidance that paper records containing NPI must be disposed of in a manner that prevents unauthorized access, typically through cross-cut shredding, burning or pulping. Electronic media must be destroyed or sanitized so the information cannot be retrieved.

The Privacy Rule

The Privacy Rule requires covered businesses to deliver privacy notices to customers describing what information is collected, how it is shared and how customers can opt out of certain sharing. This is the document you receive from your bank or insurance company once a year.

The Pretexting Rule

The Pretexting Rule prohibits using false pretenses to access consumer financial information. This is anti-fraud legislation aimed at people impersonating customers or representatives to extract financial data.

GLBA and Massachusetts 201 CMR 17.00

For Massachusetts businesses, GLBA compliance and Massachusetts 201 CMR 17.00 compliance overlap significantly. Both require written information security programs. Both require documented disposal practices. Both apply to roughly the same scope of businesses, though 201 CMR 17.00 covers any business holding personal information of MA residents, not just financial services.

Practical implication: a single WISP that satisfies both GLBA and 201 CMR 17.00 is the efficient path. Disposal practices that meet GLBA standards typically meet 201 CMR 17.00 standards as well. Our Privacy Laws Every MA Business Should Know guide breaks down both frameworks in detail.

GLBA Penalties for Non-Compliance

GLBA violations carry significant penalties. The Federal Trade Commission can pursue civil penalties up to $100,000 per violation against the institution, plus up to $10,000 per violation against officers and directors. State Attorneys General can also bring action. Massachusetts AG enforcement under MGL c.93H can layer on top of federal penalties.

Beyond financial penalties, GLBA violations frequently trigger:

  • Mandatory consumer notification of any breach affecting their information
  • Credit monitoring offers paid by the offending business
  • Class-action lawsuits from affected consumers
  • Reputational damage that takes years to recover from
  • Increased insurance premiums and stricter terms on future renewals
  • Loss of regulatory licenses for severely repeat offenders

Recent FTC enforcement actions in the financial services sector have settled in the $1 to $50 million range, with smaller individual penalties layered on top. The cost of compliance is far below any of those outcomes.

Practical Disposal Compliance Steps

Most metro Boston businesses can satisfy the GLBA disposal requirement with five practical steps.

Step 1: Document your disposal procedures in your WISP. Specify what happens to paper records, electronic media, hard drives and backup tapes at end of retention. Name the destruction method and the documentation kept.

Step 2: Engage a HIPAA-aware shredding vendor. Ask for a written contract that specifies safeguards comparable to your own. We provide standard contract language that satisfies GLBA service provider requirements at signup.

Step 3: Use cross-cut industrial shredding. Office strip-cut shredders that produce reassemblable output do not always satisfy the “reasonable measures” standard under enforcement scrutiny. Cross-cut to NIST 800-88 unreadable particles clears the bar by a wide margin.

Step 4: Retain Certificates of Destruction. File every Certificate by date. In an FTC inquiry or state AG investigation, the Certificate is the evidence that backs up your “we destroyed it properly” claim.

Step 5: Train staff annually. Disposal awareness should be part of your annual security training. Staff need to know what counts as NPI and where it goes (locked console, secure drop bin, etc.) when they are done with it.

Our service plans cover steps 2 through 4 directly. Steps 1 and 5 are your responsibility, but we provide template language and training materials on request.

Common GLBA Disposal Mistakes We See

Five mistakes show up repeatedly in our intake conversations with new clients who recently discovered they have GLBA exposure.

Mistake 1, treating recycling as disposal. Tossing paper into the curbside recycling bin does not satisfy GLBA. The recycling stream is unsecured and accessible to multiple parties. Disposal must prevent unauthorized access until the records are physically destroyed.

Mistake 2, assuming office shredders satisfy compliance. Office shredders typically lack the destruction documentation that enforcement actions look for. Without a Certificate of Destruction, “we shredded it ourselves” is not an audit-supportable answer.

Mistake 3, missing service provider contracts. Using a shredding vendor without a written contract leaves a gap in the GLBA service provider oversight requirement. Get the contract signed before the first pickup.

Mistake 4, ignoring electronic media. Hard drives, USB sticks and backup tapes containing NPI must be physically destroyed or cryptographically sanitized at end of life. Reformatting is not enough. See our hard drive destruction service for compliant media destruction.

Mistake 5, no documentation retention schedule. Records held past their required retention period become liabilities. Without a destruction calendar, old NPI accumulates in storage rooms and basements waiting to be exposed by a flood, fire or theft.

Frequently Asked GLBA Questions

Does GLBA apply to small business with only a handful of customers?
Yes. GLBA applies based on activity, not size. A solo financial advisor with 20 client relationships handles NPI just like a regional bank with 200,000. The Safeguards Rule expectations scale to business size but disposal compliance is required at every scale.
What is “non-public personal information” exactly?
NPI is any personally identifiable financial information that is not publicly available. Account numbers, balances, transaction history, credit scores, Social Security numbers, financial planning details and similar items qualify. Information available in public phone directories or property records does not.
How long must we retain customer financial records?
GLBA itself does not set retention periods. Other rules do: tax records 7 years (IRS), broker-dealer records 6 years (SEC 17a-4), bank records vary by Federal Reserve guidance. Massachusetts adds its own retention requirements for some categories. Build a retention schedule that incorporates every applicable rule for each record type.
Do we need a separate WISP for GLBA versus 201 CMR 17.00?
No. A unified WISP that addresses both GLBA Safeguards Rule and Massachusetts 201 CMR 17.00 requirements is the standard approach. The two frameworks substantially overlap. One document can serve both compliance regimes.
What does professional shredding cost for our office?
Drop-off and off-site pickup both run 99 cents per pound. Off-site pickup adds transportation starting at $129 (zone-based). Scheduled office service starts at $195/month with locked consoles included. See our pricing page for full rate detail.
Can we be audited just for GLBA disposal compliance?
Yes. The FTC and state Attorneys General can investigate disposal practices as part of broader GLBA compliance reviews, often triggered by consumer complaints, breach reports or whistleblower tips. Disposal documentation is a standard line of inquiry.

Get GLBA-Compliant Shredding Across Metro Boston.

Service provider contract included. Certificate every job. Same documentation across all 14 metro Boston cities. Free quote within 24 hours.