What Is the Gramm-Leach-Bliley Act?
Plain-English guide to GLBA for Massachusetts financial businesses. Who is covered, what disposal rules apply, the real penalties and how to comply without overhauling your operations.
The Gramm-Leach-Bliley Act, often shortened to GLBA, is the federal law that requires “financial institutions” to safeguard consumer financial information. Most Massachusetts business owners hear “financial institution” and assume the law applies only to banks. The reality is much broader. If your business handles consumer credit data, account information or similar financial details, GLBA likely applies to you, including your disposal practices.
This guide walks through who GLBA covers, what the law requires, what enforcement actually looks like and the practical disposal practices that satisfy compliance for metro Boston businesses.
Who GLBA Covers
The Federal Trade Commission’s GLBA Safeguards Rule defines “financial institution” as any business “significantly engaged in financial activities.” That definition is intentionally wide. The most commonly covered metro Boston businesses include:
- Banks, credit unions and savings institutions
- Tax preparers and CPA firms
- Mortgage brokers and mortgage lenders
- Real estate brokerages handling closings or financing referrals
- Auto dealers offering financing
- Investment advisers and broker-dealers
- Financial planners and wealth managers
- Check cashers, payday lenders and money transmitters
- Insurance agencies handling annuities, mortgage insurance or similar products
- Consumer reporting agencies (credit bureaus) and resellers
- Debt collectors and credit counseling services
If your business collects, processes or stores consumer financial information from someone you have a customer relationship with, GLBA likely applies. The threshold is whether you have customers with non-public personal information (NPI) on file. Email addresses and contact info alone do not trigger GLBA. Account numbers, Social Security numbers, financial transaction history or credit information do.
What GLBA Requires
GLBA has three primary rules: the Privacy Rule, the Safeguards Rule and the Pretexting Rule. For most metro Boston businesses, the Safeguards Rule is where compliance work concentrates.
The Safeguards Rule
The Safeguards Rule requires every covered business to develop, implement and maintain a written information security program (WISP). The WISP must include:
- A designated qualified individual responsible for the program
- A written risk assessment identifying foreseeable threats to customer information
- Safeguards designed to control the identified risks, including access controls, encryption, multi-factor authentication and disposal practices
- Service provider oversight, with contracts requiring those providers to maintain comparable safeguards
- Regular monitoring, testing and training
- An incident response plan
- Written annual reporting to the board or senior leadership
Disposal of customer information is explicitly identified as one of the required safeguards. The FTC has issued specific guidance that paper records containing NPI must be disposed of in a manner that prevents unauthorized access, typically through cross-cut shredding, burning or pulping. Electronic media must be destroyed or sanitized so the information cannot be retrieved.
The Privacy Rule
The Privacy Rule requires covered businesses to deliver privacy notices to customers describing what information is collected, how it is shared and how customers can opt out of certain sharing. This is the document you receive from your bank or insurance company once a year.
The Pretexting Rule
The Pretexting Rule prohibits using false pretenses to access consumer financial information. This is anti-fraud legislation aimed at people impersonating customers or representatives to extract financial data.
GLBA and Massachusetts 201 CMR 17.00
For Massachusetts businesses, GLBA compliance and Massachusetts 201 CMR 17.00 compliance overlap significantly. Both require written information security programs. Both require documented disposal practices. Both apply to roughly the same scope of businesses, though 201 CMR 17.00 covers any business holding personal information of MA residents, not just financial services.
Practical implication: a single WISP that satisfies both GLBA and 201 CMR 17.00 is the efficient path. Disposal practices that meet GLBA standards typically meet 201 CMR 17.00 standards as well. Our Privacy Laws Every MA Business Should Know guide breaks down both frameworks in detail.
GLBA Penalties for Non-Compliance
GLBA violations carry significant penalties. The Federal Trade Commission can pursue civil penalties up to $100,000 per violation against the institution, plus up to $10,000 per violation against officers and directors. State Attorneys General can also bring action. Massachusetts AG enforcement under MGL c.93H can layer on top of federal penalties.
Beyond financial penalties, GLBA violations frequently trigger:
- Mandatory consumer notification of any breach affecting their information
- Credit monitoring offers paid by the offending business
- Class-action lawsuits from affected consumers
- Reputational damage that takes years to recover from
- Increased insurance premiums and stricter terms on future renewals
- Loss of regulatory licenses for severely repeat offenders
Recent FTC enforcement actions in the financial services sector have settled in the $1 to $50 million range, with smaller individual penalties layered on top. The cost of compliance is far below any of those outcomes.
Practical Disposal Compliance Steps
Most metro Boston businesses can satisfy the GLBA disposal requirement with five practical steps.
Step 1: Document your disposal procedures in your WISP. Specify what happens to paper records, electronic media, hard drives and backup tapes at end of retention. Name the destruction method and the documentation kept.
Step 2: Engage a HIPAA-aware shredding vendor. Ask for a written contract that specifies safeguards comparable to your own. We provide standard contract language that satisfies GLBA service provider requirements at signup.
Step 3: Use cross-cut industrial shredding. Office strip-cut shredders that produce reassemblable output do not always satisfy the “reasonable measures” standard under enforcement scrutiny. Cross-cut to NIST 800-88 unreadable particles clears the bar by a wide margin.
Step 4: Retain Certificates of Destruction. File every Certificate by date. In an FTC inquiry or state AG investigation, the Certificate is the evidence that backs up your “we destroyed it properly” claim.
Step 5: Train staff annually. Disposal awareness should be part of your annual security training. Staff need to know what counts as NPI and where it goes (locked console, secure drop bin, etc.) when they are done with it.
Our service plans cover steps 2 through 4 directly. Steps 1 and 5 are your responsibility, but we provide template language and training materials on request.
Common GLBA Disposal Mistakes We See
Five mistakes show up repeatedly in our intake conversations with new clients who recently discovered they have GLBA exposure.
Mistake 1, treating recycling as disposal. Tossing paper into the curbside recycling bin does not satisfy GLBA. The recycling stream is unsecured and accessible to multiple parties. Disposal must prevent unauthorized access until the records are physically destroyed.
Mistake 2, assuming office shredders satisfy compliance. Office shredders typically lack the destruction documentation that enforcement actions look for. Without a Certificate of Destruction, “we shredded it ourselves” is not an audit-supportable answer.
Mistake 3, missing service provider contracts. Using a shredding vendor without a written contract leaves a gap in the GLBA service provider oversight requirement. Get the contract signed before the first pickup.
Mistake 4, ignoring electronic media. Hard drives, USB sticks and backup tapes containing NPI must be physically destroyed or cryptographically sanitized at end of life. Reformatting is not enough. See our hard drive destruction service for compliant media destruction.
Mistake 5, no documentation retention schedule. Records held past their required retention period become liabilities. Without a destruction calendar, old NPI accumulates in storage rooms and basements waiting to be exposed by a flood, fire or theft.
Frequently Asked GLBA Questions
Does GLBA apply to small business with only a handful of customers?
What is “non-public personal information” exactly?
How long must we retain customer financial records?
Do we need a separate WISP for GLBA versus 201 CMR 17.00?
What does professional shredding cost for our office?
Can we be audited just for GLBA disposal compliance?
Get GLBA-Compliant Shredding Across Metro Boston.
Service provider contract included. Certificate every job. Same documentation across all 14 metro Boston cities. Free quote within 24 hours.