Congressional Research Service examines GLBA framework and recent financial data privacy bills
On July 14, the Congressional Research Service (CRS) published an insight titled “Financial Data Privacy in the 119th Congress,” providing an overview of the GLBA’s Title V provisions and summarizing recent legislative efforts to amend that framework. The insight explained that the GLBA is built on two pillars: (i) privacy standards that impose disclosure requirements and limit disclosure of certain consumers’ information; and (ii) security standards that require institutions to implement practices safeguarding that information from unauthorized access, use and disclosure, which are implemented respectively through the Privacy Rule, known as Regulation P, and the Safeguards Rule. The insight noted that rulemaking authority for the Privacy Rule through Regulation P is vested in four agencies, while the FTC holds rulemaking authority for the Safeguards Rule, and that most financial regulators retain some supervisory or enforcement authority to ensure institutions within their jurisdictions comply with both rules.
As previously covered by InfoBytes, the House Committee on Financial Services held a hearing in March on modernizing the GLBA. The insight noted that committee leadership has since announced a joint effort with the House Committee on Energy and Commerce to advance data privacy legislation intended to create a uniform national framework for data protection across the financial industry and broader economy, namely H.R. 8398, the Guidelines for Use, Access, and Responsible Disclosure (GUARD) Financial Data Act. The insight further noted that a prior bill from the 118th Congress, the Data Privacy Act of 2023, would have expanded certain data privacy protections to consumers in addition to customers, required notice of data usage purposes, established a right to data deletion, and prohibited states from enacting privacy protections that differ from federal standards.