GLBA Exemption From State Privacy Laws: The Five States That No Longer Exempt Financial Institutions
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Fifteen of the twenty comprehensive state privacy laws exempt GLBA-regulated financial institutions at the entity level, which puts the whole organization outside the law. Five do not: California, Connecticut, Minnesota, Montana, and Oregon. In those five the carve-out attaches to the data rather than the company, or survives only for chartered banks and credit unions, so every piece of personal information a lender, servicer, fintech, or adviser holds that is not nonpublic personal information under GLBA carries full access, correction, deletion, and opt-out rights on a 45-day clock.
That list got longer twice in the space of a year, and both changes drew the same line: chartered banks and credit unions kept a pass, and almost nobody else did. Montana eliminated its broad exemption on October 1, 2025. Connecticut's expired on July 1, 2026. If your compliance program still rests on the sentence "we are a GLBA entity, so state privacy laws do not apply to us," it is now wrong in five states, and wrong in the two that most recently changed.
Which states have a GLBA entity-level exemption and which do not
The table below covers the five states without a broad entity-level exemption. The other fifteen comprehensive-law states, including Texas, Virginia, Colorado, Utah, Delaware, New Jersey, Iowa, Tennessee, and Florida, still exempt GLBA-regulated financial institutions at the entity level. Exemption language is amended more often than any other part of these statutes, so confirm a row against the current text before you rely on it.
| State | GLBA exemption scope | Who still gets an entity-level pass | In force since | Applicability threshold |
|---|---|---|---|---|
| California CCPA and CPRA | Data level only. Never had an entity-level exemption. | Nobody | Jan 1, 2020 | $26,625,000 revenue, or 100,000 consumers, or 50 percent of revenue from selling |
| Oregon OCPA | Narrow entity plus data level. No exemption for GLBA entities as such. | Oregon-defined financial institutions: banks, credit unions, affiliates directly in financial activities | Jul 1, 2024 | 100,000 consumers, or 25,000 plus 25 percent of revenue from selling |
| Minnesota MCDPA | Narrow entity plus data level. Data carve-out also covers NPI intermingled by licensed mortgage originators and servicers. | Chartered banks and credit unions, affiliates principally in financial activities | Jul 31, 2025 | 100,000 consumers, or 25,000 plus 25 percent of revenue from selling |
| Montana MCDPA | Narrow entity plus data level. Senate Bill 297 removed the broad exemption. | Chartered banks and credit unions and their affiliates | Oct 1, 2025 | 25,000 consumers |
| Connecticut CTDPA | Narrow entity plus data level. Senate Bill 1295 replaced the blanket exemption. | Banks, credit unions, certain insurers, regulated broker-dealers and investment advisers | Jul 1, 2026 | 35,000 consumers |
Read the third column carefully, because it is where the money is. Montana Senate Bill 297 was signed May 8, 2025 and took effect October 1, 2025. Connecticut Senate Bill 1295 was signed June 24, 2025 and took effect July 1, 2026. Both preserved the exemption for depository institutions and took it away from everyone else. The population that moved back into scope is the non-depository half of the industry: mortgage lenders and servicers, consumer finance companies, fintechs and payment firms, debt collectors, money transmitters, auto dealers that extend credit, tax preparers, and accounting firms. A community bank in Montana was largely unaffected. The nonbank mortgage servicer down the street was not.
Does the CCPA apply to financial institutions?
Yes, to the institution, and this has been true since the law took effect. California exempts personal information collected, processed, sold, or disclosed pursuant to the Gramm-Leach-Bliley Act. It does not exempt the company holding that information. A bank, lender, or insurer that meets any one of the CCPA applicability thresholds is a covered business for every category of personal information it holds that falls outside GLBA.
In practice that turns out to be a lot. Website and mobile app analytics on public-facing pages, including everything logged before a person applies for anything. Advertising audiences, campaign data, and purchased or modeled prospect lists. Newsletter subscribers, branch and webinar event registrations, and satisfaction surveys run through a third-party platform. Business-to-business contacts at your commercial clients. And your own employees, job applicants, and contractors, whose California exemption expired on January 1, 2023 and who now generate a growing share of employee subject access requests.
What is the difference between an entity-level and a data-level exemption?
An entity-level exemption removes the organization from the law. If you qualify, the statute does not reach you, you have no consumer rights obligations, no privacy notice duties under that law, and nothing to build. A data-level exemption removes specific categories of information from the law while leaving the organization fully covered. You still owe consumer rights, you still owe notices, you still owe deadlines, and for each incoming request you have to work out which records are carved out and which are not.
The operational difference is enormous, and it is not a question you can answer once and file away. It has to be answered per request, per record, per system, because a single consumer can be a customer for one product, a marketing lead for a second, and a job applicant for a third, with only the first sitting behind GLBA. Healthcare organizations hit exactly the same wall, and the split there runs nine to six rather than fifteen to five: see the HIPAA entity-level versus data-level breakdown by state.
Does GLBA give consumers a right to access or delete their data?
No. Title V of the Gramm-Leach-Bliley Act creates no right of access, no right to correct, no right to delete, and no right to a portable copy. The only individual right it creates is the right to opt out of the disclosure of nonpublic personal information to nonaffiliated third parties, after you have given the required notice and subject to a list of exceptions. That is the entire consumer-facing rights framework, and it is why a financial institution that loses its entity-level exemption typically has no request process at all to build on.
The Privacy Rule appears in three places depending on your regulator: Regulation P at 12 CFR Part 1016 for CFPB-supervised institutions, 16 CFR Part 313 for FTC-supervised ones, and Regulation S-P for SEC registrants. None of them contain an access right. The Safeguards Rule at 16 CFR Part 314 does not either, though it does contain something useful, which is the next section.
The Safeguards Rule already asked you for the inventory a request needs
Section 314.4(c)(2) requires you to identify and manage the data, personnel, devices, systems, and facilities that enable your business purposes, in accordance with their relative importance and your risk strategy. That is a data inventory obligation, and it is the closest thing GLBA has to a discovery requirement. Most programs satisfy it with a spreadsheet of systems and a data-flow diagram, which is defensible for a security audit and useless the moment someone asks what you hold about one named person.
A consumer request is a person-level query against every system you own. The mortgage origination platform and the servicing system are the easy part, because a loan file is structured and someone already knows where it is: it is the same file an underwriting system reads for income, liabilities, and collateral. The hard part is the CRM, the marketing automation tool, the analytics warehouse, the call recording vendor, the chat transcripts, the collections platform, and the four SaaS tools a regional team signed up for without telling anyone. That is what personal data discovery is for, and doing it well satisfies both the Safeguards Rule inventory and the state request obligation with one body of work.
While you are in that part of the rule, note the deadline that arrived on May 13, 2024: notify the FTC as soon as possible and no later than 30 days after discovering a security event involving the unencrypted customer information of at least 500 consumers. It runs on a different clock from every state breach law you already track.
How long do you have to respond?
Forty-five days from receipt in all five states, with one extension of up to 45 additional days where reasonably necessary, provided you tell the consumer about the extension and the reason within the original window. Verification time runs inside the 45 days rather than pausing them, which is the single most common way an institution with no existing workflow loses the month. Connecticut, Minnesota, Montana, and Oregon also require a conspicuous appeal process for a denial. The full picture across every state, including the two that do not use 45 plus 45, is in the guide to data subject request deadlines by state.
What to do about it
Start by working out which of the five states actually reach you, because the thresholds differ sharply and Montana's 25,000 and Connecticut's 35,000 are low enough that a regional lender clears them without noticing. Connecticut dropped from 100,000 to 35,000 in the same 2026 amendment package that took the GLBA exemption away, so two changes compounded on the same date. The threshold guide to which state privacy laws apply to your business walks the counting rules.
Then draw the line between GLBA data and everything else, in writing, per system, before a request arrives rather than during one. Then build an intake that can receive a request, log the date, and start a clock, because the failure mode in every enforcement file worth reading is not a bad decision about scope. It is a request that landed in an unwatched mailbox and sat there. The operational side, including the discovery, the manifest, and the approval trail, is what the GLBA compliance page for financial institutions covers in detail. Obtainer helps you comply. It is not legal advice, and the exemption analysis stays with your team.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.