DEFINITION
GLBA (Gramm-Leach-Bliley Act)
The U.S. federal law requiring financial institutions to protect the nonpublic personal information of their customers and explain their data-sharing practices.
In depth
The Gramm-Leach-Bliley Act (GLBA, 1999) imposes three main obligations on financial institutions — broadly defined to include banks, mortgage lenders, insurers, investment advisers, and many fintech companies. The Privacy Rule requires annual privacy notices and limits sharing of nonpublic personal information (NPI) with non-affiliated third parties. The Safeguards Rule, updated in 2023 under FTC authority, requires a written information security program with specific technical controls including encryption, multi-factor authentication, and penetration testing. The Pretexting provisions prohibit social engineering to obtain NPI. Pasting customer NPI — account numbers, income data, transaction histories, Social Security Numbers — into an AI model that has not signed a data-use agreement aligned with GLBA is, in most analyses, a disclosure of NPI to a third party that the Safeguards Rule requires institutions to prevent.
Examples
- A loan officer pasting a customer's full credit application — including SSN, income, and employer — into ChatGPT to 'summarise the risk profile.'
- A financial adviser using a personal Gemini account to draft a client portfolio review, embedding account numbers and holdings.
- An insurance underwriter routing applicant medical and financial history through an unsanctioned AI tool to speed up pricing.
How Locke handles glba (gramm-leach-bliley act)
Locke detects NPI categories — Social Security Numbers, account numbers, routing numbers, credit card numbers, income figures, and customer names in financial contexts — locally, before any prompt leaves the device. Because all detection is on-device, Sonomos itself is not a third party receiving NPI under GLBA.
See the productRelated terms
- CCPA
The California Consumer Privacy Act and its 2023 successor, the CPRA — the United States' most influential state-level privacy law.
- Personally Identifiable Information (PII)
Any information that can identify a specific person, either directly (name, SSN) or in combination with other data (zip code + birthdate).
- Data Loss Prevention (DLP)
A category of security tooling that inspects outbound data flows to prevent sensitive content from leaving an organisation's control.