The Gramm-Leach-Bliley Act (GLBA) is a U.S. federal law that requires financial institutions to protect the nonpublic personal information (NPI) customers share with them, and that protection duty extends to every document that contains it. In practice, GLBA document handling means three things: knowing which files hold NPI, restricting who can open those files, and keeping a record that shows you did both.
Most teams do not fail GLBA because they ignored it. They fail because NPI is scattered across loan files, account applications, tax documents, and email attachments, and nobody has a reliable way to find it all before an exam, a breach, or a customer request forces the issue.
Who has to follow GLBA document handling rules?
GLBA applies to any business that is "significantly engaged" in financial activities, a definition the Federal Trade Commission (FTC) interprets broadly. Banks and credit unions are the obvious cases, but the FTC's Safeguards Rule also reaches mortgage brokers, payday lenders, tax preparers, auto dealers that arrange financing, collection agencies, and financial advisors.
- Banks, credit unions, and savings institutions
- Mortgage lenders and brokers
- Consumer finance and payday lending companies
- Tax preparation firms handling client financial data
- Auto dealers that originate or arrange financing
- Investment advisors and financial planners
- Debt collectors and collection agencies
If your business touches a customer's account numbers, income, credit history, or payment information as part of financial services, GLBA's document-handling obligations almost certainly apply, whether or not the business calls itself a "bank."
What counts as nonpublic personal information in a document?
Nonpublic personal information is any personally identifiable financial information a customer provides to get a financial product or service, plus anything derived from that transaction. In document form, this shows up constantly: a loan application with a Social Security number, a bank statement attached to an underwriting file, a signed W-9, a payoff letter listing an account balance.
The FTC's Safeguards Rule (16 C.F.R. Part 314) does not name specific document types. It defines the data, and any document carrying that data inherits the obligation. That is why a document-by-document inventory, not a folder-level guess, is the only reliable starting point.
| Document type | Typical NPI present | Handling risk if mishandled |
|---|---|---|
| Loan or credit applications | SSN, income, employment history | Identity theft if leaked or misfiled |
| Bank and account statements | Account numbers, balances, transaction history | Fraud, unauthorized transfers |
| Tax documents (W-2, 1099, W-9) | SSN or EIN, income | Tax fraud, identity theft |
| Underwriting and appraisal files | Property value, income, credit data | Discrimination or pricing disputes if exposed |
| Collections correspondence | Account status, balance owed, contact details | Harassment or privacy complaints if mishandled |
What does the Safeguards Rule actually require?
The FTC's Safeguards Rule guidance, last significantly updated in 2021, requires covered institutions to maintain a written information security program with specific, auditable elements. For document handling, the relevant pieces are access controls, encryption of NPI at rest and in transit, secure disposal, and a written incident response plan.
- Designate a qualified individual responsible for the information security program
- Complete a written risk assessment that identifies where NPI lives, including in documents
- Implement access controls so only authorized staff can open NPI-bearing files
- Encrypt NPI at rest and in transit, or apply an equivalent compensating control
- Dispose of NPI securely once it is no longer needed for business purposes
- Monitor and log access to systems holding NPI
- Test the program's effectiveness at least annually
None of these steps are optional add-ons. The 2021 amendment added the annual testing and access-logging requirements specifically because examiners kept finding institutions that had a policy document but no way to show it was followed.
How is GLBA different from CCPA or GDPR for document compliance?
GLBA is sector-specific and mandatory for covered financial institutions, while CCPA and GDPR are broader consumer-privacy laws that apply regardless of industry. A financial institution operating in California may need to satisfy both GLBA's Safeguards Rule and CCPA's data-handling requirements at once, and the two frameworks do not map onto each other cleanly. Our CCPA vs. CPRA breakdown covers how those state rules differ from a document-handling standpoint; GLBA layers on top rather than replacing them.
The practical difference for document teams: GLBA is prescriptive about security controls (encryption, access logs, disposal), while CCPA and GDPR are prescriptive about consumer rights (access, deletion, opt-out). A compliant financial institution needs both a secured document store and a way to honor a deletion or access request without breaking the audit trail the Safeguards Rule demands.
How long should a financial institution keep documents with NPI?
GLBA itself does not set retention periods; those come from other regulations layered on top, such as Regulation B, the Bank Secrecy Act, and IRS recordkeeping rules, which commonly range from three to seven years depending on the document type. What GLBA does require is that once a retention period ends, disposal of NPI-bearing documents is secure, not just deleted from a visible folder. Our document retention schedule guide walks through how to build a defensible schedule; the disposal method matters as much as the timeline for GLBA purposes.
What breaks first when a small financial firm tries to comply manually?
Two things break first: the inventory and the access log. Manually tagging every loan file, statement, and application that contains NPI across shared drives and email is realistic for a hundred documents and unrealistic for ten thousand. And once files are scattered, proving who accessed what, for the annual test the Safeguards Rule requires, becomes a reconstruction project instead of a report.
This is where document analysis tools earn their keep. HiDocument scans uploaded PDFs, Word files, and images to flag where sensitive data patterns appear and lets a compliance team review, summarize, and export findings without manually opening every file. It does not replace a written information security program, but it removes the slowest part of building one: finding out what you actually have.
Create a free HiDocument account to run your first NPI inventory pass over a batch of loan or account files and see what the scan surfaces.
What should a firm do if it cannot afford enterprise compliance software?
The most common objection here is cost: enterprise GRC (governance, risk, and compliance) platforms built for large banks price out small lenders, tax preparers, and independent financial advisors entirely. That objection is legitimate, but the underlying task, finding and controlling NPI in documents, does not require an enterprise platform to start. A free tier that lets a compliance officer run a handful of files through a document scanner each month is enough to build the habit and establish the initial inventory the Safeguards Rule's risk assessment calls for. Scaling up to bulk processing only becomes necessary once the file volume outgrows manual review, and at that point the cost is offset by the hours saved and the exam risk reduced.
How do you start a GLBA document review this week?
Pick one file category, loan applications, tax documents, or account statements, and run every file from the last quarter through a document analysis pass to confirm what NPI each one actually contains. HiDocument's report grader can score a sample of files against a custom rubric covering data fields present, access markings, and retention flags, which gives a compliance officer a starting inventory in an afternoon instead of a quarter. From there, apply access controls to whichever shared drive or folder holds the highest concentration of NPI first, since that is where a single misconfiguration causes the most exposure.
HiDocument is a document analysis tool, not a law firm, and nothing here is legal advice; confirm your specific obligations under GLBA and any state law with qualified counsel before finalizing a compliance program.
Frequently Asked Questions
Does GLBA apply to small mortgage brokers and independent tax preparers?
Yes. The FTC's Safeguards Rule applies to any business significantly engaged in financial activities, which explicitly includes mortgage brokers, tax preparers who handle client financial data, and similar small firms, not just large banks.
What is the difference between GLBA and the Safeguards Rule?
GLBA is the underlying federal law passed in 1999. The Safeguards Rule is the FTC regulation, updated in 2021, that spells out the specific security controls, including access management and encryption, financial institutions must implement to comply with GLBA's data protection requirements.
Can NPI be stored in regular email attachments?
GLBA does not ban email attachments outright, but any NPI sent or stored that way must meet the same encryption and access-control standards as NPI stored elsewhere, which most default email setups do not provide without added controls.
Who is responsible for GLBA compliance inside a company?
The Safeguards Rule requires every covered institution to designate a single qualified individual responsible for overseeing the information security program, even at small firms where that person also holds another role.
Does deleting a file from a folder satisfy GLBA's disposal requirement?
No. Secure disposal under the Safeguards Rule means NPI cannot be reconstructed from the storage medium, which typically requires certified data wiping or physical destruction, not a standard file deletion that leaves recoverable data behind.
How often does a financial institution need to test its information security program?
The 2021 Safeguards Rule amendment requires covered institutions to test or monitor the effectiveness of their program's key controls at least annually, with continuous monitoring as an accepted alternative to periodic penetration testing.