top of page
Search

GLBA PII: What It Is, Examples, Requirements, and How to Protect It

Writer: sam diago
sam diago
Sep 7
9 min read

GLBA PII refers to personally identifiable financial information protected under the Gramm-Leach-Bliley Act (GLBA). The GLBA regulates how covered financial institutions collect, use, disclose, and safeguard consumers' nonpublic personal information (NPI). This information can include names, addresses, Social Security numbers, account information, payment history, loan balances, and other financial information connected to a financial product or service.

For organizations that collect or manage sensitive financial information, understanding GLBA PII is important for privacy, security, data governance, and regulatory compliance. Solix provides additional information about GLBA requirements and the protection of sensitive financial information.

What Is GLBA PII?

GLBA PII generally refers to personally identifiable financial information that falls within the GLBA's definition of nonpublic personal information (NPI).

The Federal Trade Commission explains that NPI includes personally identifiable financial information collected by a financial institution in connection with providing a financial product or service, unless the information is otherwise publicly available.

In practical terms, GLBA-protected information can reveal something about an individual's:

  • Identity

  • Financial accounts

  • Transactions

  • Credit activity

  • Loan relationships

  • Payment history

  • Financial products or services

  • Relationship with a financial institution

An important distinction is that GLBA itself generally uses the term "nonpublic personal information" rather than simply "PII." Therefore, when organizations refer to "GLBA PII," they are often describing personally identifiable financial information that is protected as NPI under GLBA requirements.

What Does GLBA Stand For?

GLBA stands for the Gramm-Leach-Bliley Act.

The law, enacted in 1999, addresses consumer financial privacy and requires covered financial institutions to protect consumers' personal financial information. The FTC explains that the GLBA requires financial institutions to explain their information-sharing practices and safeguard sensitive customer information.

The GLBA framework includes important privacy and security requirements, including the:

  • Privacy Rule

  • Safeguards Rule

  • Pretexting provisions

Together, these requirements address how financial institutions handle and protect consumer information.

What Information Is Considered GLBA PII?

The exact information covered depends on the context in which it is collected and how it relates to financial products or services.

The FTC identifies several examples of information that can constitute NPI.

Names and Contact Information

Information such as a person's name, address, and other identifying information can fall within GLBA protection when collected in connection with a financial product or service.

Social Security Numbers

A Social Security number collected through a financial application is a common example of sensitive financial information protected under GLBA.

Account Numbers

Bank account numbers, credit account numbers, loan account numbers, and related identifiers can constitute protected information.

Payment History

Information about payments, transactions, deposits, withdrawals, or financial obligations may be protected.

Loan Information

Details concerning loans, balances, applications, and servicing relationships can be covered.

Credit or Debit Card Purchases

Transaction information associated with financial products may also constitute NPI.

Customer Relationships

In some circumstances, even information indicating that an individual is a customer of a particular financial institution can be considered nonpublic personal information.

GLBA PII Examples

A simple example helps illustrate the concept.

Suppose a consumer applies for a mortgage. The financial institution may collect:

  • Full name

  • Home address

  • Social Security number

  • Income

  • Employment information

  • Bank account information

  • Credit information

  • Loan amount

  • Payment history

Information supplied as part of the application can fall within the GLBA's definition of NPI because it is personally identifiable financial information collected in connection with providing a financial product or service.

Another example is a bank's customer database containing:

Customer name + account number + transaction history + contact information

Because the information is connected to the individual's financial relationship with the institution, it can be subject to GLBA protections.

GLBA PII vs. General PII

Not all PII is automatically GLBA PII.

This is an important distinction for data governance teams.

Information

Potential GLBA Relevance

Name

Depends on context

Home address

Depends on context

Social Security number

Often highly relevant

Bank account number

Financial information

Loan information

Financial information

Payment history

Financial information

Credit card transaction

Financial information

Customer relationship with lender

May be NPI

Publicly available information

May be excluded from NPI depending on circumstances

The context in which information is collected matters.

For example, a person's name on a public website is not necessarily GLBA-protected NPI. However, that same person's name included in a lender's customer database can be part of protected information when associated with a financial relationship.

The FTC specifically notes that a list derived even partially from NPI can itself be considered NPI.

Is GLBA PII the Same as NPI?

Not exactly.

NPI means Nonpublic Personal Information, which is the terminology used by the GLBA Privacy and Safeguards Rules.

GLBA's definition of NPI includes:

Personally identifiable financial information + certain lists or groupings derived from that information, excluding information that is publicly available under the rule.

Therefore, "GLBA PII" is commonly used as a convenient way to describe personally identifiable information protected under GLBA, but organizations should use the more precise regulatory term NPI when documenting compliance requirements.

What Is the GLBA Privacy Rule?

The GLBA Privacy Rule addresses consumer financial privacy.

The rule requires covered financial institutions to provide privacy notices describing their policies and practices concerning consumer information. Under applicable circumstances, institutions must also provide consumers with an opportunity to opt out of certain disclosures of NPI to nonaffiliated third parties.

The FTC explains that privacy notices must describe relevant categories of information collected and disclosed and categories of affiliates and nonaffiliated third parties with whom information may be shared.

What Is the GLBA Safeguards Rule?

The GLBA Safeguards Rule focuses on protecting customer information through an information security program.

The FTC states that covered financial institutions under its jurisdiction must have measures in place to keep customer information secure and must take steps concerning affiliates and service providers that safeguard customer information in their care.

The rule requires covered organizations to develop, implement, and maintain administrative, technical, and physical safeguards designed to protect customer information.

This makes data security a central part of GLBA compliance.

How Should Organizations Protect GLBA PII?

Protecting GLBA PII requires more than simply storing data in a secure database.

A comprehensive protection strategy should address the entire information lifecycle.

1. Discover Sensitive Data

Organizations need visibility into where financial information exists.

GLBA-related information may be distributed across:

  • Databases

  • File systems

  • Email

  • Documents

  • Cloud storage

  • Data warehouses

  • Data lakes

  • Applications

  • Backups

  • Archives

Data discovery helps identify where sensitive information is stored and processed.

2. Classify Information

Once discovered, sensitive information should be classified according to its risk and regulatory requirements.

Organizations can create classifications such as:

Public → Internal → Confidential → GLBA/NPI Restricted

Classification makes it easier to determine which security controls apply.

3. Control Access

Access to GLBA-related information should be limited to authorized individuals.

Organizations can implement:

  • Role-based access control

  • Least-privilege access

  • Multi-factor authentication

  • Privileged-access controls

  • Access reviews

The FTC's Safeguards Rule guidance includes requirements concerning security measures such as access and authentication controls.

4. Encrypt Sensitive Information

Encryption can reduce the risk of unauthorized access to financial information during storage and transmission.

Organizations should evaluate encryption requirements for:

  • Databases

  • File systems

  • Cloud environments

  • Backups

  • Data transfers

  • Portable devices

5. Monitor Data Usage

Monitoring can help organizations identify unusual access patterns and potential security incidents.

Useful controls include:

  • Audit logging

  • Security monitoring

  • User activity monitoring

  • Data access alerts

  • Incident detection

6. Secure Third Parties

Financial institutions often work with service providers that may have access to customer information.

GLBA security responsibilities therefore extend beyond the organization's internal systems. The FTC states that covered financial institutions have responsibilities concerning affiliates and service providers that safeguard customer information in their care.

7. Dispose of Data Securely

Sensitive information that is no longer required should be disposed of according to applicable policies and regulatory requirements.

Data retention and secure disposal should be part of the broader information lifecycle.

Why Is GLBA PII Difficult to Manage?

Large financial organizations often have data distributed across numerous systems.

For example, one customer's information might exist in:

CRM → Loan application → Database → Email → Document repository → Data warehouse → Backup → Archive

This creates several challenges.

Data Sprawl

The more systems containing sensitive data, the harder it becomes to maintain visibility.

Duplicate Information

The same customer information may appear in multiple applications and repositories.

Legacy Systems

Older applications may contain financial information without modern discovery, classification, or security controls.

Unstructured Data

Sensitive financial information may exist in documents, spreadsheets, PDFs, emails, and other unstructured sources.

Cloud Data

Organizations must also understand where information resides across cloud services and whether appropriate security controls are applied.

GLBA PII and Data Discovery

Data discovery can play an important role in GLBA compliance because organizations cannot adequately protect information they cannot locate.

A useful data discovery process can identify:

What data exists?

Where is it stored?

Who can access it?

How sensitive is it?

How long has it been retained?

Does the organization still need it?

These questions help organizations build a clearer picture of their regulated data environment.

GLBA PII and Data Governance

GLBA compliance is closely connected to effective data governance.

A mature governance program can establish:

  • Data ownership

  • Data classification

  • Retention policies

  • Access policies

  • Data lineage

  • Audit controls

  • Privacy requirements

  • Security standards

  • Data quality requirements

This approach can help organizations move beyond reactive compliance toward continuous information governance.

GLBA PII Data Lifecycle

A useful way to manage sensitive financial information is to consider the full lifecycle:

Create → Collect → Classify → Store → Access → Use → Share → Retain → Archive → Dispose

Security and governance controls should be evaluated throughout each stage.

For example:

Collection: Identify what financial information is being collected.

Storage: Protect information using appropriate technical controls.

Access: Restrict information to authorized users.

Sharing: Apply appropriate privacy and third-party controls.

Retention: Keep information according to documented requirements.

Disposition: Securely remove information when it is no longer required.

Common GLBA PII Compliance Challenges

Organizations commonly face several operational challenges when managing sensitive financial information.

Lack of Data Visibility

Security teams may not know where all copies of sensitive information reside.

Inconsistent Classification

Different departments may classify similar information differently.

Excessive Access

Employees or applications may have broader access than required.

Third-Party Risk

Service providers may process or store customer information.

Legacy Data

Old archives and systems may contain information that is no longer actively used but still requires protection.

Incomplete Retention Policies

Organizations may retain sensitive data longer than necessary because they lack effective lifecycle controls.

Best Practices for GLBA PII Management

A practical GLBA information-protection strategy should include:

Discover: Find sensitive financial information across structured and unstructured repositories.

Classify: Identify GLBA/NPI data based on context and sensitivity.

Protect: Apply appropriate access controls, encryption, monitoring, and other safeguards.

Govern: Establish policies for ownership, retention, sharing, and disposal.

Monitor: Continuously evaluate access and security activity.

Review: Periodically assess whether controls remain effective.

Document: Maintain evidence of policies, procedures, assessments, and security activities.

GLBA PII vs. HIPAA PHI vs. PCI Data

GLBA PII is sometimes confused with information regulated under other frameworks.

Framework

Primary Data Focus

GLBA

Consumer financial information/NPI

HIPAA

Protected health information

PCI DSS

Payment card data

GDPR

Personal data of individuals within its scope

CCPA/CPRA

Personal information under California privacy law

An organization may be subject to multiple frameworks simultaneously.

For example, a financial services company accepting credit cards may need to consider both GLBA obligations and payment-card security requirements.

Frequently Asked Questions About GLBA PII

What is GLBA PII?

GLBA PII generally refers to personally identifiable financial information protected as nonpublic personal information under the Gramm-Leach-Bliley Act.

What does PII mean under GLBA?

Under GLBA, the more precise regulatory concept is nonpublic personal information (NPI). NPI includes personally identifiable financial information collected in connection with providing a financial product or service, subject to the rule's exclusions and definitions.

What are examples of GLBA PII?

Examples can include names, addresses, Social Security numbers, account numbers, transaction information, payment history, loan information, account balances, and credit or debit card purchase information when covered by the GLBA definition of NPI.

Is a Social Security number GLBA PII?

A Social Security number collected in connection with a financial product or service can be part of GLBA-protected nonpublic personal information.

Is a bank account number protected by GLBA?

Yes, a bank or financial account number can constitute protected NPI when it falls within the GLBA's definition of personally identifiable financial information.

Is a customer's name considered GLBA PII?

It depends on the context. A name by itself is not necessarily GLBA-protected information. However, a customer's name associated with a financial relationship can be part of protected NPI.

Does GLBA protect publicly available information?

The GLBA definition of NPI excludes information that qualifies as publicly available information under the applicable rules. The FTC explains that the determination depends on whether the information is lawfully publicly available and other conditions.

What is the difference between GLBA PII and NPI?

NPI is the regulatory term used by the GLBA rules. "GLBA PII" is commonly used to describe personally identifiable information protected under GLBA, particularly financial information.

Does GLBA require encryption?

The GLBA Safeguards Rule requires covered financial institutions to maintain an information security program with appropriate safeguards. Specific security measures depend on the organization and applicable requirements; encryption can be an important security control but should be considered as part of a broader security program.

Does GLBA apply only to banks?

No. GLBA can apply to a broader range of financial institutions and companies significantly engaged in financial activities. The FTC notes that the definition can cover businesses that may not traditionally be viewed as banks.

Why is GLBA PII important for data governance?

GLBA PII requires organizations to understand where sensitive financial information resides, who can access it, how it is used and shared, how long it is retained, and how it is protected. Effective data governance can help support these controls.

Conclusion

GLBA PII is personally identifiable financial information that falls within the GLBA framework for protecting nonpublic personal information. Examples may include Social Security numbers, account information, loan details, transaction records, payment history, and information identifying a consumer's relationship with a financial institution.

For financial institutions, protecting this information requires a combination of privacy practices, information security, access controls, data discovery, classification, monitoring, third-party oversight, retention management, and secure disposal.

The GLBA Privacy Rule addresses privacy and information-sharing requirements, while the Safeguards Rule focuses on protecting customer information through an appropriate information security program.

Ultimately, organizations should view GLBA PII protection as an ongoing data-governance and security responsibility, not simply a one-time compliance exercise. Understanding what information is covered and where that information exists is the foundation for protecting it effectively.

 
 
 

Recent Posts

See All

Comments


bottom of page