Loading Vaultize
Skip to main content

Compliance/Global/GLBA

Three instruments: sixteen leave evidence in the file.

The Act makes every financial institution responsible for the security and confidentiality of customers' nonpublic personal information. Vaultize adds records that stay with the file.

  • Safeguards Rule, 16 CFR 314
  • FTC notification since 13 May 2024
  • Capability mapping, not legal advice

6801(a)Statute, 15 U.S.C. 6801

It is the policy of the Congress that each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers' nonpublic personal information.

Discover & Classify · Vaultize Seal

  1. USC

    Statute, 15 U.S.C. 6801

    1 of 9

    • 6801
    • 6802
    • 6803
    • 6804
    • 6805
    • 6806
    • 6807
    • 6808
    • 6809
  2. 314

    Safeguards Rule, 16 CFR 314

    2 of 6

    • 314.1
    • 314.2
    • 314.3
    • 314.4
    • 314.5
    • 314.6
  3. 313

    Privacy Rule, 16 CFR 313

    0 of 18

    • 313.1
    • 313.2
    • 313.3
    • 313.4
    • 313.5
    • 313.6
    • 313.7
    • 313.8
    • 313.9
    • 313.10
    • 313.11
    • 313.12
    • 313.13
    • 313.14
    • 313.15
    • 313.16
    • 313.17
    • 313.18
Read againstGramm-Leach-Bliley Act, Title V, and the FTC Safeguards Rule, 16 CFR Part 31415 U.S.C. 6801 and 16 CFR Part 314 · Compliance required from 9 June 2023
16of 33 sections across three instruments

The answer in 30 seconds

Vaultize adds file-level records to sixteen provisions: the statute's affirmative obligation and standards duty, and twelve of the Safeguards Rule's elements for access, encryption, disposal, monitoring, service providers, incident response and FTC notification. The written information security program, the Qualified Individual, the risk assessment, penetration testing, workforce training and the consumer notice-and-opt-out process under the Privacy Rule sit outside a governed file, with the financial institution.

The instruments in one view

Three instruments. Thirty-three sections. Where file evidence lands.

GLBA is not one certification. The statute sets the obligation, the Safeguards Rule sets the technical duties, and the Privacy Rule sets the notice and opt-out process. All three are shown together below. The Safeguards Rule is where a governed file's evidence concentrates. Entities under CFPB jurisdiction follow the same privacy provisions under Regulation P, 12 CFR Part 1016, rather than Part 313.

USCSTATUTE, 15U.S.C. 6801314SAFEGUARDS RULE, 16CFR 314313PRIVACY RULE, 16CFR 313

USC

Statute, 15 U.S.C. 6801

Sections 6801 to 6809. The policy obligation to protect customer information, the limits on disclosing it to nonaffiliated third parties, the notice and enforcement provisions, and the definitions that carry through the Subtitle.

Outcomes the file can evidence

How Vaultize contributes
Encryption sealed into the document with customer-controlled keys, and the classification and per-access records around it, are the kind of continuing technical measure the affirmative obligation in section 6801 points to. Vaultize does not decide what counts as nonpublic personal information or discharge the obligation itself.
Evidence to retain
Discovery inventory. Classification history. Encryption on the file with customer-controlled keys. Per-access records.

Provision by provision

What each provision asks. What the file can answer.

Wording is quoted from 15 U.S.C. 6801 to 6809 and from 16 CFR Part 314, current as of 3 September 2026 per the eCFR. Longer provisions are excerpted. Each row is a capability mapping, not legal advice. Read the Act and the Rules and take advice on applicability, roles and technical implementation.

Using this page

Where these rows fit in a GLBA programme.

The Safeguards Rule's 2021 amendments carried a compliance deadline of 9 June 2023. The FTC notification duty at 314.4(j) has applied since 13 May 2024. The rows above are evidence for the obligations that touch documents.

  1. 1

    Confirm financial institution status

    Sections 6809 and 314.2. Whether the entity is a "financial institution" under the Act and the Rule, and the definitions that follow from that status.

  2. 2

    Build the information security program

    Sections 314.3 and 314.4(a) to (b). The written programme, the Qualified Individual, and the risk assessment it rests on.

  3. 3

    Apply the safeguards

    Section 314.4(c). Access controls, encryption, multi-factor authentication, secure disposal and monitoring and logging. These rows belong here.

    Bring the sixteen rows above as evidence of the safeguards section 314.4(c) requires and the objectives section 314.3 sets.

  4. 4

    Monitor, oversee providers and respond to incidents

    Section 314.4(d) to (h). Testing and monitoring, service-provider oversight, and the written incident response plan.

  5. 5

    Notify the FTC

    Section 314.4(j). Notification to the Federal Trade Commission when a notification event involves at least 500 consumers.

Responsibility boundary

Controls support compliance. They are not legal advice.

Vaultize contributes technical measures and evidence for customer information held in documents. It does not write the information security program, designate a Qualified Individual, perform the risk assessment, run penetration testing or vulnerability assessments, train personnel, select or oversee service providers, hold the incident response plan, or notify the Federal Trade Commission. It does not manage the consumer notices and opt-out rights the Privacy Rule requires. This page is a capability mapping, not legal advice. Read the Act and the Rules and take qualified advice before relying on this page.

“You shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of any customer information at issue.”

16 CFR 314.3(a), FTC Safeguards Rule

A practical next step

Bring one document that carries customer information.

We will show which provisions the governed document can evidence today. We will name the owner responsible for the rest.

Request a compliance mapping session