The Gramm-Leach-Bliley Act is the 1999 US law governing how financial institutions handle and protect consumers' nonpublic personal information, including the Privacy Rule and the Safeguards Rule. It is the long-standing privacy and data-security backdrop against which US open banking and the CFPB's 1033 rule operate — the pre-existing obligation that any US financial-data-sharing regime has to work within.
Gramm-Leach-Bliley Act
The Gramm-Leach-Bliley Act (GLBA) is the US financial-privacy law that was governing consumer financial data long before anyone said “open banking.” Its Privacy Rule constrains how institutions share nonpublic personal information, and its Safeguards Rule requires them to secure it — the backdrop the CFPB’s 1033 rule and the whole US data-sharing effort have to operate within.
- The Privacy Rule - Governs when and how a financial institution may disclose a consumer’s nonpublic personal information, and requires privacy notices.
- The Safeguards Rule - Requires a written information-security program to protect that data — the security floor beneath any API that exposes it.
- The pre-existing regime - Unlike the UK or Australia, where open banking arrived into a purpose-built regime, US open banking is layered on top of a twenty-five-year-old privacy law, which shapes how §1033 and the CFPB rule can operate.
GLBA is a useful reminder that the US did not lack financial-privacy law — it lacked an access mandate. The security and privacy obligations were always there; what was missing until the CFPB rule was the requirement to let a consumer port their data through an API. That gap, not a privacy vacuum, is what produced the fragmented US market I scored.
Referenced in API Evangelist papers
This regulation shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this regulation in the context of a real sector.
The State of US Banking APIs
The pre-existing US financial-privacy regime the 1033 rule has to operate within — the security-and-privacy floor beneath open banking.