What Non-Financial Institutions Need to Know About Gramm-Leach-Bliley

Society of Corporate Compliance and Ethics (SCCE)
Contact
The Gramm-Leach-Bliley Act (GLBA) is typically referred to in the context of financial institutions. It requires offerers of consumer financial products to explain how they share information and protect sensitive data.

It’s not, however, only banks that fall under GLBA’s umbrella. New rules will affect retailers offering credit terms to their customers, higher education institutions that administer federal student aid and others a well, explains Kayne McGladrey, Field CISO for See more +

The Gramm-Leach-Bliley Act (GLBA) is typically referred to in the context of financial institutions. It requires offerers of consumer financial products to explain how they share information and protect sensitive data.

It’s not, however, only banks that fall under GLBA’s umbrella. New rules will affect retailers offering credit terms to their customers, higher education institutions that administer federal student aid and others a well, explains Kayne McGladrey, Field CISO for Hyperproof.

The FTC, has set June 2023 as the deadline for compliance with the revised GLBA Safeguards Rule. It requires that affected organizations:

Have a qualified individual to implement and enforce an information security plan

Conduct a periodic cybersecurity risk assessment

Implement cybersecurity controls to manage those risk

Document who has access to customer data

Assess the risks of applications that can access the data

Securely destroy old data

Periodically test the controls to verify their effectiveness

In addition, staff needs to be trained, there must be a written incidence response plan and ongoing testing.

It is a considerable commitment, Kayne points out, but since it overlaps with the requirements of the European General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), many organizations may already have significant structures in place.

Even so, it’s important to conduct a gap analysis, he advises, to ensure all the requirements are being met.

Listen in to learn more about what Gramm-Leach-Bliley now requires for your organization. See less -

Embed
Copy

Written by:

Society of Corporate Compliance and Ethics (SCCE)
Contact
more
less

Society of Corporate Compliance and Ethics (SCCE) on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide