GLBA compliance — meeting the Gramm-Leach-Bliley Act's data-security obligations, chiefly the FTC's Safeguards Rule — is now one of the most concrete compliance duties a lender carries. What began as a principles-based expectation is today a prescriptive checklist of technical and administrative controls, backed by a breach-notification requirement that took effect in 2024. This guide covers who the rule reaches, what it requires, and how to put it into practice.
Who the Safeguards Rule covers
The FTC's Safeguards Rule (16 CFR Part 314) applies to "financial institutions" under the FTC's jurisdiction, and the definition is broad. It includes mortgage lenders, finance companies, mortgage brokers, account servicers, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, and entities acting as finders. In short: if your organization extends credit, services loans, or handles consumer financial information, assume the rule applies to you.
What the amended Safeguards Rule requires
The 2021 amendments, which became fully effective in June 2023, turned the rule into a specific set of requirements. The core obligations:
A written information security program
Every covered institution must develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards appropriate to its size, complexity, and the sensitivity of the customer information it handles.
A Qualified Individual
You must designate a single Qualified Individual to oversee the program. This person implements and enforces it and reports to your board or governing body at least annually. They can be an employee or an external provider, but the institution keeps responsibility for compliance.
A written risk assessment
You must conduct — and periodically update — a written risk assessment identifying reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information.
Technical safeguards
The rule requires specific controls: multi-factor authentication for anyone accessing customer information; encryption of customer information both in transit and at rest; access controls limiting information to authorized users; and secure disposal of customer information no later than two years after the last date it was used.
Testing and monitoring
Absent effective continuous monitoring, the rule requires annual penetration testing and vulnerability assessments at least every six months, plus additional assessments when there are material changes to operations.
Breach notification (effective May 2024)
As of May 13, 2024, covered institutions must notify the FTC as soon as possible — and no later than 30 days after discovery — of a security breach involving the unencrypted information of at least 500 consumers. Information counts as unencrypted if the encryption key was also acquired by an unauthorized person. The notice is filed through the FTC's electronic reporting form and includes the types of information involved, the date range of the event, the number of consumers affected, and whether law enforcement has requested a delay.
The small-business exception
Institutions that maintain customer information on fewer than 5,000 consumers are exempt from several requirements — the written risk assessment, the penetration testing and vulnerability assessment mandates, the written incident response plan, and board reporting. They must still maintain reasonable safeguards appropriate to their size and operations.
A GLBA compliance checklist
- Designate a Qualified Individual to oversee the information security program.
- Develop and maintain a written information security program.
- Conduct and document a written risk assessment.
- Implement multi-factor authentication for all systems holding customer information.
- Encrypt customer information in transit and at rest.
- Limit access to authorized users, and securely dispose of data within two years of last use.
- Run annual penetration testing and semiannual vulnerability assessments (absent continuous monitoring).
- Maintain a written incident response plan.
- Configure FTC breach-notification procedures for events affecting 500 or more consumers.
- Report to the board or senior management at least annually.
- Assess service providers and require contractual security commitments.
Where Salesforce and LASER fit
For lenders on Salesforce, the platform supplies a strong foundation — multi-factor authentication, role-based access controls, field-level security, encryption at rest and in transit, and audit logging — but the Safeguards Rule makes it your responsibility to configure those correctly and document them as part of your written program. LASER Credit Access adds controls specific to credit bureau data: a permission-set architecture that governs who can pull and view credit reports, and protection of managed fields on the credit report records. LASER helps you surface and track these obligations; it does not discharge your institution's legal duties for you.
For how GLBA sits alongside the other rules that govern a lending stack, see our adverse action notice guide, the OFAC checks guide, and our lending compliance software.
This article is for informational and educational purposes only and is not legal advice. Requirements change and vary by institution type; confirm current requirements with qualified legal counsel before acting.
