Glossary

DEFINITION

GLBA (Gramm-Leach-Bliley Act)

The U.S. federal law requiring financial institutions to protect the nonpublic personal information of their customers and explain their data-sharing practices.

In depth

The Gramm-Leach-Bliley Act (GLBA, 1999) imposes three main obligations on financial institutions — broadly defined to include banks, mortgage lenders, insurers, investment advisers, and many fintech companies. The Privacy Rule requires annual privacy notices and limits sharing of nonpublic personal information (NPI) with non-affiliated third parties. The Safeguards Rule, updated in 2023 under FTC authority, requires a written information security program with specific technical controls including encryption, multi-factor authentication, and penetration testing. The Pretexting provisions prohibit social engineering to obtain NPI. Pasting customer NPI — account numbers, income data, transaction histories, Social Security Numbers — into an AI model that has not signed a data-use agreement aligned with GLBA is, in most analyses, a disclosure of NPI to a third party that the Safeguards Rule requires institutions to prevent.

Examples

  • A loan officer pasting a customer's full credit application — including SSN, income, and employer — into ChatGPT to 'summarise the risk profile.'
  • A financial adviser using a personal Gemini account to draft a client portfolio review, embedding account numbers and holdings.
  • An insurance underwriter routing applicant medical and financial history through an unsanctioned AI tool to speed up pricing.

How Locke handles glba (gramm-leach-bliley act)

Locke detects NPI categories — Social Security Numbers, account numbers, routing numbers, credit card numbers, income figures, and customer names in financial contexts — locally, before any prompt leaves the device. Because all detection is on-device, Sonomos itself is not a third party receiving NPI under GLBA.

See the product