Why It Matters
A recent Congressional Research Service report examines growing congressional interest in updating the Gramm-Leach-Bliley Act (GLBA), enacted in 1999, which CRS describes as the most comprehensive federal framework governing financial data privacy. More than 25 years after its enactment, lawmakers are considering how the law should address a financial system that relies increasingly on data, data processors, technology, and data aggregators. The United States still lacks a single federal law providing a comprehensive framework for data privacy and protection.
Congress faces competing pressures as it considers how to update the law. A central policy dispute is whether a new federal standard should preempt state privacy laws. Under current law, states may establish stricter financial privacy protections than those imposed by GLBA.
The Federal Trade Commission (FTC) has rulemaking authority for the Safeguards Rule, which requires covered financial institutions to develop and implement information security programs, identify and assess risks to customer information, and address risks involving their operations and service providers. Rulemaking authority for the Privacy Rule is divided among four federal agencies.
The Big Picture
GLBA applies broadly to institutions engaged in activities that are “financial in nature,” including lending, exchanging or safeguarding money, insuring against loss, providing investment services, and underwriting. Its privacy framework generally rests on two pillars: rules governing disclosure and use of consumers' nonpublic personal information and security requirements intended to protect that information from unauthorized access, use, or disclosure.
Congressional interest has increasingly focused on giving consumers greater control over their financial data. In April, House Financial Services Committee leaders introduced H.R. 8398, the Guidelines for Use, Access, and Responsible Disclosure (GUARD) Financial Data Act, as part of a joint data privacy initiative with the House Energy and Commerce Committee. The bill would amend GLBA by requiring financial institutions to limit data collection to information that is “adequate, relevant, and reasonably necessary” for a product or service. It would also require data aggregators and third parties to provide notice and an opportunity to opt out before using consumers' login credentials to access financial accounts.
The GUARD Financial Data Act would also establish GLBA Title V as a uniform national standard for financial data privacy and security, preempting certain state requirements. It would expand disclosures about how financial institutions use data, require affirmative consent before certain sensitive personal information may be collected or disclosed, give current and former customers greater access to their data, and allow former customers to request deletion subject to specified exceptions.
A similar proposal advanced further in the previous Congress. H.R. 1165 was reported out of committee during the 118th Congress and would have established nationwide financial privacy standards, expanded certain protections from “customers” with ongoing relationships to “consumers” with more limited relationships, required financial institutions to disclose the purposes for which they used personal information, created a right to request deletion, and prohibited states from imposing privacy requirements different from the federal standard. The measure did not become law.
The modernization debate also reflects changes in how financial data move beyond traditional banks. Data aggregators and third-party financial technology providers can obtain or process consumers' financial information, raising questions about which entities and information should fall under GLBA and how consumers should control access to their data. CRS identifies those changes as a central reason Congress is reconsidering the framework.
The Bottom Line
Congress is actively seeking to modernize GLBA by reconsidering the types of information and institutions covered by federal financial privacy rules and expanding how consumers can access and control their data. The current GUARD Financial Data Act would move toward a single national financial privacy standard while imposing new data-minimization, consent, access, and deletion requirements on financial institutions.
The debate leaves Congress with a central trade-off: whether creating a uniform federal standard would provide clearer protections nationwide or displace stronger privacy requirements that states are currently permitted to enact.
Access the Legis1 platform for comprehensive political news, data, and insights.
Spot something wrong? Report an issue with this article