CFPB Proposes New GLB Privacy Notice Rule
Time 2 Minute Read
Categories: FCRA, Financial Privacy

On May 6, 2014, the Consumer Financial Protection Bureau (“CFPB”) announced a new proposed rule impacting privacy notices that financial institutions are required to issue under the Gramm-Leach-Bliley Act (“GLB”). Under the current GLB Privacy Rule, financial institutions must mail an annual privacy notice (the “GLB Privacy Notice”) to their customers that sets forth how they collect, use and disclose those customers’ nonpublic personal information (“NPI”) and whether customers may limit such sharing.

Under the proposed rule, certain financial institutions may forego the annual mailing requirement and instead include a brief disclosure in a billing statement or other communication that the GLB Privacy Notice is available online, then post that notice “in a clear and conspicuous manner” on the institution’s website. Financial institutions also must inform consumers that they may request a paper version of the GLB Privacy Notice by calling a toll-free number. To qualify for this online privacy notice option:

  • A financial institution must not share NPI with nonaffiliated third parties in a manner that requires an opt-out right be provided to customers;
  • The GLB Privacy Notice must not include an opt out pursuant to the Fair Credit Reporting Act;
  • The GLB Privacy Notice cannot be the only notice the financial institution provides to satisfy FCRA requirements;
  • The GLB Privacy Notice must not have changed since the last time it was provided to customers; and
  • The GLB Privacy Notice must use the model form regulators have developed to comply with the notice requirement.

If a financial institution does not meet all of the requirements listed above, it must continue to mail the GLB Privacy Notice annually to its customers. In announcing the proposed rule, CFPB Director Richard Cordray noted that the changes would both improve customers’ abilities to “find and access privacy policies” and reduce the costs “for industry to provide disclosures.”

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page