GLBA PII: What It Is, Examples, Requirements, and How to Protect It
GLBA PII refers to personally identifiable financial information protected under the Gramm-Leach-Bliley Act (GLBA). The GLBA regulates how covered financial institutions collect, use, disclose, and safeguard consumers' nonpublic personal information (NPI). This information can include names, addresses, Social Security numbers, account information, payment history, loan balances, and other financial information connected to a financial product or service.
For organizations that collect or manage sensitive financial information, understanding GLBA PII is important for privacy, security, data governance, and regulatory compliance. Solix provides additional information about GLBA requirements and the protection of sensitive financial information.
What Is GLBA PII?
GLBA PII generally refers to personally identifiable financial information that falls within the GLBA's definition of nonpublic personal information (NPI).
The Federal Trade Commission explains that NPI includes personally identifiable financial information collected by a financial institution in connection with providing a financial product or service, unless the information is otherwise publicly available.
In practical terms, GLBA-protected information can reveal something about an individual's:
Identity
Financial accounts
Transactions
Credit activity
Loan relationships
Payment history
Financial products or services
Relationship with a financial institution
An important distinction is that GLBA itself generally uses the term "nonpublic personal information" rather than simply "PII." Therefore, when organizations refer to "GLBA PII," they are often describing personally identifiable financial information that is protected as NPI under GLBA requirements.
What Does GLBA Stand For?
GLBA stands for the Gramm-Leach-Bliley Act.
The law, enacted in 1999, addresses consumer financial privacy and requires covered financial institutions to protect consumers' personal financial information. The FTC explains that the GLBA requires financial institutions to explain their information-sharing practices and safeguard sensitive customer information.
The GLBA framework includes important privacy and security requirements, including the:
Privacy Rule
Safeguards Rule
Pretexting provisions
Together, these requirements address how financial institutions handle and protect consumer information.
What Information Is Considered GLBA PII?
The exact information covered depends on the context in which it is collected and how it relates to financial products or services.
The FTC identifies several examples of information that can constitute NPI.
Names and Contact Information
Information such as a person's name, address, and other identifying information can fall within GLBA protection when collected in connection with a financial product or service.
Social Security Numbers
A Social Security number collected through a financial application is a common example of sensitive financial information protected under GLBA.
Account Numbers
Bank account numbers, credit account numbers, loan account numbers, and related identifiers can constitute protected information.
Payment History
Information about payments, transactions, deposits, withdrawals, or financial obligations may be protected.
Loan Information
Details concerning loans, balances, applications, and servicing relationships can be covered.
Credit or Debit Card Purchases
Transaction information associated with financial products may also constitute NPI.
Customer Relationships
In some circumstances, even information indicating that an individual is a customer of a particular financial institution can be considered nonpublic personal information.
GLBA PII Examples
A simple example helps illustrate the concept.
Suppose a consumer applies for a mortgage. The financial institution may collect:
Full name
Home address
Social Security number
Income
Employment information
Bank account information
Credit information
Loan amount
Payment history
Information supplied as part of the application can fall within the GLBA's definition of NPI because it is personally identifiable financial information collected in connection with providing a financial product or service.
Another example is a bank's customer database containing:
Customer name + account number + transaction history + contact information
Because the information is connected to the individual's financial relationship with the institution, it can be subject to GLBA protections.
GLBA PII vs. General PII
Not all PII is automatically GLBA PII.
This is an important distinction for data governance teams.
Information | Potential GLBA Relevance |
Name | Depends on context |
Home address | Depends on context |
Social Security number | Often highly relevant |
Bank account number | Financial information |
Loan information | Financial information |
Payment history | Financial information |
Credit card transaction | Financial information |
Customer relationship with lender | May be NPI |
Publicly available information | May be excluded from NPI depending on circumstances |
The context in which information is collected matters.
For example, a person's name on a public website is not necessarily GLBA-protected NPI. However, that same person's name included in a lender's customer database can be part of protected information when associated with a financial relationship.
The FTC specifically notes that a list derived even partially from NPI can itself be considered NPI.
Is GLBA PII the Same as NPI?
Not exactly.
NPI means Nonpublic Personal Information, which is the terminology used by the GLBA Privacy and Safeguards Rules.
GLBA's definition of NPI includes:
Personally identifiable financial information + certain lists or groupings derived from that information, excluding information that is publicly available under the rule.
Therefore, "GLBA PII" is commonly used as a convenient way to describe personally identifiable information protected under GLBA, but organizations should use the more precise regulatory term NPI when documenting compliance requirements.
What Is the GLBA Privacy Rule?
The GLBA Privacy Rule addresses consumer financial privacy.
The rule requires covered financial institutions to provide privacy notices describing their policies and practices concerning consumer information. Under applicable circumstances, institutions must also provide consumers with an opportunity to opt out of certain disclosures of NPI to nonaffiliated third parties.
The FTC explains that privacy notices must describe relevant categories of information collected and disclosed and categories of affiliates and nonaffiliated third parties with whom information may be shared.
What Is the GLBA Safeguards Rule?
The GLBA Safeguards Rule focuses on protecting customer information through an information security program.
The FTC states that covered financial institutions under its jurisdiction must have measures in place to keep customer information secure and must take steps concerning affiliates and service providers that safeguard customer information in their care.
The rule requires covered organizations to develop, implement, and maintain administrative, technical, and physical safeguards designed to protect customer information.
This makes data security a central part of GLBA compliance.
How Should Organizations Protect GLBA PII?
Protecting GLBA PII requires more than simply storing data in a secure database.
A comprehensive protection strategy should address the entire information lifecycle.
1. Discover Sensitive Data
Organizations need visibility into where financial information exists.
GLBA-related information may be distributed across:
Databases
File systems
Email
Documents
Cloud storage
Data warehouses
Data lakes
Applications
Backups
Archives
Data discovery helps identify where sensitive information is stored and processed.
2. Classify Information
Once discovered, sensitive information should be classified according to its risk and regulatory requirements.
Organizations can create classifications such as:
Public → Internal → Confidential → GLBA/NPI Restricted
Classification makes it easier to determine which security controls apply.
3. Control Access
Access to GLBA-related information should be limited to authorized individuals.
Organizations can implement:
Role-based access control
Least-privilege access
Multi-factor authentication
Privileged-access controls
Access reviews
The FTC's Safeguards Rule guidance includes requirements concerning security measures such as access and authentication controls.
4. Encrypt Sensitive Information
Encryption can reduce the risk of unauthorized access to financial information during storage and transmission.
Organizations should evaluate encryption requirements for:
Databases
File systems
Cloud environments
Backups
Data transfers
Portable devices
5. Monitor Data Usage
Monitoring can help organizations identify unusual access patterns and potential security incidents.
Useful controls include:
Audit logging
Security monitoring
User activity monitoring
Data access alerts
Incident detection
6. Secure Third Parties
Financial institutions often work with service providers that may have access to customer information.
GLBA security responsibilities therefore extend beyond the organization's internal systems. The FTC states that covered financial institutions have responsibilities concerning affiliates and service providers that safeguard customer information in their care.
7. Dispose of Data Securely
Sensitive information that is no longer required should be disposed of according to applicable policies and regulatory requirements.
Data retention and secure disposal should be part of the broader information lifecycle.
Why Is GLBA PII Difficult to Manage?
Large financial organizations often have data distributed across numerous systems.
For example, one customer's information might exist in:
CRM → Loan application → Database → Email → Document repository → Data warehouse → Backup → Archive
This creates several challenges.
Data Sprawl
The more systems containing sensitive data, the harder it becomes to maintain visibility.
Duplicate Information
The same customer information may appear in multiple applications and repositories.
Legacy Systems
Older applications may contain financial information without modern discovery, classification, or security controls.
Unstructured Data
Sensitive financial information may exist in documents, spreadsheets, PDFs, emails, and other unstructured sources.
Cloud Data
Organizations must also understand where information resides across cloud services and whether appropriate security controls are applied.
GLBA PII and Data Discovery
Data discovery can play an important role in GLBA compliance because organizations cannot adequately protect information they cannot locate.
A useful data discovery process can identify:
What data exists?
Where is it stored?
Who can access it?
How sensitive is it?
How long has it been retained?
Does the organization still need it?
These questions help organizations build a clearer picture of their regulated data environment.
GLBA PII and Data Governance
GLBA compliance is closely connected to effective data governance.
A mature governance program can establish:
Data ownership
Data classification
Retention policies
Access policies
Data lineage
Audit controls
Privacy requirements
Security standards
Data quality requirements
This approach can help organizations move beyond reactive compliance toward continuous information governance.
GLBA PII Data Lifecycle
A useful way to manage sensitive financial information is to consider the full lifecycle:
Create → Collect → Classify → Store → Access → Use → Share → Retain → Archive → Dispose
Security and governance controls should be evaluated throughout each stage.
For example:
Collection: Identify what financial information is being collected.
Storage: Protect information using appropriate technical controls.
Access: Restrict information to authorized users.
Sharing: Apply appropriate privacy and third-party controls.
Retention: Keep information according to documented requirements.
Disposition: Securely remove information when it is no longer required.
Common GLBA PII Compliance Challenges
Organizations commonly face several operational challenges when managing sensitive financial information.
Lack of Data Visibility
Security teams may not know where all copies of sensitive information reside.
Inconsistent Classification
Different departments may classify similar information differently.
Excessive Access
Employees or applications may have broader access than required.
Third-Party Risk
Service providers may process or store customer information.
Legacy Data
Old archives and systems may contain information that is no longer actively used but still requires protection.
Incomplete Retention Policies
Organizations may retain sensitive data longer than necessary because they lack effective lifecycle controls.
Best Practices for GLBA PII Management
A practical GLBA information-protection strategy should include:
Discover: Find sensitive financial information across structured and unstructured repositories.
Classify: Identify GLBA/NPI data based on context and sensitivity.
Protect: Apply appropriate access controls, encryption, monitoring, and other safeguards.
Govern: Establish policies for ownership, retention, sharing, and disposal.
Monitor: Continuously evaluate access and security activity.
Review: Periodically assess whether controls remain effective.
Document: Maintain evidence of policies, procedures, assessments, and security activities.
GLBA PII vs. HIPAA PHI vs. PCI Data
GLBA PII is sometimes confused with information regulated under other frameworks.
Framework | Primary Data Focus |
GLBA | Consumer financial information/NPI |
HIPAA | Protected health information |
PCI DSS | Payment card data |
GDPR | Personal data of individuals within its scope |
CCPA/CPRA | Personal information under California privacy law |
An organization may be subject to multiple frameworks simultaneously.
For example, a financial services company accepting credit cards may need to consider both GLBA obligations and payment-card security requirements.
Frequently Asked Questions About GLBA PII
What is GLBA PII?
GLBA PII generally refers to personally identifiable financial information protected as nonpublic personal information under the Gramm-Leach-Bliley Act.
What does PII mean under GLBA?
Under GLBA, the more precise regulatory concept is nonpublic personal information (NPI). NPI includes personally identifiable financial information collected in connection with providing a financial product or service, subject to the rule's exclusions and definitions.
What are examples of GLBA PII?
Examples can include names, addresses, Social Security numbers, account numbers, transaction information, payment history, loan information, account balances, and credit or debit card purchase information when covered by the GLBA definition of NPI.
Is a Social Security number GLBA PII?
A Social Security number collected in connection with a financial product or service can be part of GLBA-protected nonpublic personal information.
Is a bank account number protected by GLBA?
Yes, a bank or financial account number can constitute protected NPI when it falls within the GLBA's definition of personally identifiable financial information.
Is a customer's name considered GLBA PII?
It depends on the context. A name by itself is not necessarily GLBA-protected information. However, a customer's name associated with a financial relationship can be part of protected NPI.
Does GLBA protect publicly available information?
The GLBA definition of NPI excludes information that qualifies as publicly available information under the applicable rules. The FTC explains that the determination depends on whether the information is lawfully publicly available and other conditions.
What is the difference between GLBA PII and NPI?
NPI is the regulatory term used by the GLBA rules. "GLBA PII" is commonly used to describe personally identifiable information protected under GLBA, particularly financial information.
Does GLBA require encryption?
The GLBA Safeguards Rule requires covered financial institutions to maintain an information security program with appropriate safeguards. Specific security measures depend on the organization and applicable requirements; encryption can be an important security control but should be considered as part of a broader security program.
Does GLBA apply only to banks?
No. GLBA can apply to a broader range of financial institutions and companies significantly engaged in financial activities. The FTC notes that the definition can cover businesses that may not traditionally be viewed as banks.
Why is GLBA PII important for data governance?
GLBA PII requires organizations to understand where sensitive financial information resides, who can access it, how it is used and shared, how long it is retained, and how it is protected. Effective data governance can help support these controls.
Conclusion
GLBA PII is personally identifiable financial information that falls within the GLBA framework for protecting nonpublic personal information. Examples may include Social Security numbers, account information, loan details, transaction records, payment history, and information identifying a consumer's relationship with a financial institution.
For financial institutions, protecting this information requires a combination of privacy practices, information security, access controls, data discovery, classification, monitoring, third-party oversight, retention management, and secure disposal.
The GLBA Privacy Rule addresses privacy and information-sharing requirements, while the Safeguards Rule focuses on protecting customer information through an appropriate information security program.
Ultimately, organizations should view GLBA PII protection as an ongoing data-governance and security responsibility, not simply a one-time compliance exercise. Understanding what information is covered and where that information exists is the foundation for protecting it effectively.
Comments