GLBA Scope, NPI and Enforcement
GLBA covers financial institutions significantly engaged in financial activities and regulates nonpublic personal information (NPI). Enforcement runs through federal banking regulators, the SEC, the FTC and now the CFPB; there is no private right of action, and stricter state laws are not preempted.
How this supports CIPP/US study
Use this lesson to separate sectoral scope, data type and regulated entity before testing an exception. Continue with the CIPP/US practice exam.
A financial institution is any U.S. company significantly engaged in financial activities (banks, insurers, securities firms, payment services, check cashers, credit counselors, mortgage lenders). Nonpublic personal information (NPI) is broad: even a customer's name is NPI because it signals a financial relationship.
GLBA protects consumers (those obtaining products for personal/family/household use), but many requirements (like annual notice) apply only to customers with an ongoing relationship.
Penalties: up to $100,000 per violation for institutions; up to $10,000 per violation for officers/directors; criminal penalties for intentional violations. FIRREA adds further penalties. No private right of action exists, though notice failures may be deceptive trade practices, and stricter state laws are not preempted.
Key terms - quick answers
What is “Nonpublic personal information (NPI)”?
What is “Customer (GLBA)”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.