Obtainer
Use case

GLBA Compliance Software for Financial Institutions: Consumer Data Requests and State Privacy Rights

The exemption most financial institutions have been relying on is shrinking, and it is shrinking fastest for anyone who is not a chartered bank. California never offered a blanket pass. Oregon and Minnesota wrote theirs narrowly. Montana removed its broad version on October 1, 2025, and Connecticut's went on July 1, 2026. In those five states a consumer can ask a mortgage servicer, a nonbank lender, a fintech, an auto dealer, or an investment adviser for everything held about them, and GLBA itself gives you no request process to fall back on. Obtainer finds where that data lives across your systems, compiles one reviewable manifest, and keeps the clock.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

GLBA compliance means meeting the two rules that sit under Title V of the Gramm-Leach-Bliley Act: the Privacy Rule, implemented as Regulation P by the CFPB at 12 CFR Part 1016, as 16 CFR Part 313 by the FTC, and as Regulation S-P by the SEC, and the Safeguards Rule at 16 CFR Part 314. The Privacy Rule is about notice and opt-out. You give customers an initial and annual privacy notice, you describe when you share nonpublic personal information with nonaffiliated third parties, and you give them a way to opt out of that sharing. The Safeguards Rule is about security. You maintain a written information security program, name a qualified individual to run it, run a written risk assessment, and since May 13, 2024 you notify the FTC within 30 days of discovering a security event affecting the unencrypted customer information of at least 500 consumers. Here is what GLBA does not do, and it is the part that catches teams out: it gives a consumer no right to access their data, no right to correct it, no right to delete it, and no right to a portable copy. Those rights come from state law, and the state exemption financial institutions assume they have is disappearing. Fifteen of the twenty comprehensive state privacy laws still exempt GLBA-regulated financial institutions at the entity level, which puts the whole organization outside the law. Five do not: California, Connecticut, Minnesota, Montana, and Oregon. In those five the exemption attaches to the data rather than the company, or is narrowed to chartered banks and credit unions, so everything you hold that is not nonpublic personal information under GLBA carries full access, correction, deletion, portability, and opt-out rights on a 45-day clock. Obtainer is built for that gap. It intakes the request, verifies the requester, discovers where a person's personal data actually sits across the systems that are not your core banking or loan origination platform, separates the GLBA-covered records from the records that are in scope, compiles one source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock so it does not slip. Nothing is disclosed automatically. A human reviews, redacts, and approves everything that goes out, and you get a timestamped record of what was searched and when. Obtainer helps you comply. It is not legal advice, so the exemption analysis, the identity verification standard, and any decision to deny stay with your team. Self-serve from $49/mo.

// THE FIT

Why it fits

Privacy, compliance, and legal teams at mortgage lenders and servicers, fintechs, consumer finance companies, credit unions and community banks, broker-dealers and investment advisers, debt collectors, and accounting firms: GLBA-regulated, and now facing state consumer data requests GLBA never contemplated.

GLBA gives your customers no right to their data. Five state laws now do.

Regulation P is a notice-and-opt-out regime. It tells a consumer what you share and lets them stop some of it, and that is the extent of the individual rights it creates. There is no right of access, no right to correct, no right to delete, and no right to a portable copy anywhere in Title V. That worked as long as the state laws exempted you. In California, Connecticut, Minnesota, Montana, and Oregon they no longer do, which means the first access request many financial institutions receive arrives at an organization that has never had to build a process for one. The deadline is 45 days from receipt, with one 45-day extension if you tell the consumer why.

The entity-level exemption is going, and it is going for non-banks first

Both 2025 amendments drew the same line. Montana Senate Bill 297, signed May 8, 2025 and effective October 1, 2025, eliminated the broad GLBA entity-level exemption while preserving it for state and federally chartered banks, credit unions, and affiliates. Connecticut Senate Bill 1295, signed June 24, 2025 and effective July 1, 2026, replaced its blanket GLBA exemption with entity-level carve-outs for banks, credit unions, certain insurers, and regulated broker-dealers and investment advisers, and kept the data-level exemption for GLBA information. If you are a mortgage lender or servicer, a fintech, a consumer finance company, a debt collector, a money transmitter, an auto dealer extending credit, a tax preparer, or an accountant, you are the population these amendments were aimed at.

The Safeguards Rule already asked you for the inventory a request needs

Section 314.4(c)(2) requires you to identify and manage the data, personnel, devices, systems, and facilities that support your business purposes, weighted by importance and risk. That is a data inventory obligation, and most programs satisfy it on paper without ever producing something you could search person by person. A consumer request is the moment the gap shows, because answering it means knowing every system that holds a record about one named individual, including the marketing stack, the CRM, the analytics warehouse, the servicing vendor, and the long tail of tools nobody wrote down. The same discovery work serves both obligations.

The data outside GLBA is larger than most institutions expect

Nonpublic personal information is information you obtain in connection with providing a financial product or service to a consumer. A great deal of what you hold does not meet that description. Website and app analytics on public pages, advertising and campaign audiences, prospect and lead lists bought or built before anyone applied for anything, newsletter subscribers, branch event registrations, survey platforms, and job applicants, employees, and contractors, who have been fully in scope in California since January 1, 2023. In a data-level state every one of those categories carries access, correction, deletion, and opt-out rights, and none of them live in the system your compliance program is built around.

// FAQ

Questions

Common questions about this

What is GLBA compliance?

It is meeting the requirements of Title V of the Gramm-Leach-Bliley Act, which for most institutions means two rules. The Privacy Rule requires initial and annual privacy notices, disclosure of what nonpublic personal information you share with nonaffiliated third parties, and an opt-out mechanism. The Safeguards Rule requires a written information security program, a qualified individual to oversee it, a written risk assessment, vendor oversight, and FTC notification within 30 days of a security event affecting 500 or more consumers.

Are financial institutions exempt from the CCPA?

Not as organizations. California has never granted a GLBA entity-level exemption. The CCPA exempts personal information collected, processed, sold, or disclosed under GLBA, which is a data-level carve-out, so the business itself stays covered for everything else it holds. That includes website and marketing data, prospect lists, and since January 1, 2023, its own employees, job applicants, and contractors, plus business-to-business contacts. A bank or lender meeting the CCPA thresholds owes consumer rights on all of it.

Does GLBA give consumers the right to access or delete their data?

No. The Gramm-Leach-Bliley Act creates no right of access, no right to correct, no right to delete, and no right to data portability. The only individual right it creates is the right to opt out of the disclosure of nonpublic personal information to nonaffiliated third parties, subject to exceptions, after receiving the required notice. Any access or deletion right a customer of a financial institution has comes from state law or, for consumers in the EU and UK, from the GDPR.

Which states no longer have a GLBA entity-level exemption?

Five: California, Connecticut, Minnesota, Montana, and Oregon. California never had one. Oregon's law, effective July 1, 2024, exempts only Oregon-defined financial institutions such as banks and credit unions and affiliates directly engaged in financial activities. Minnesota, effective July 31, 2025, exempts chartered banks and credit unions and certain affiliates rather than all GLBA entities. Montana removed its broad exemption on October 1, 2025, and Connecticut on July 1, 2026. The other fifteen comprehensive state laws still exempt GLBA-covered financial institutions at the entity level.

What is the difference between the GLBA Privacy Rule and the Safeguards Rule?

The Privacy Rule governs disclosure. It sets what you must tell consumers about your information-sharing practices and when they can opt out of sharing with nonaffiliated third parties. The Safeguards Rule governs security. It sets the administrative, technical, and physical controls you must put around customer information, including the written program, the qualified individual, the risk assessment, encryption, multi-factor authentication, vendor oversight, and the 30-day FTC breach notification for events affecting at least 500 consumers.

Does a mortgage lender or fintech have to answer a data subject request?

In California, Connecticut, Minnesota, Montana, and Oregon, yes, for any personal data that is not nonpublic personal information under GLBA, assuming you meet that state's applicability threshold. Nonbank lenders, mortgage servicers, fintechs, and consumer finance companies are precisely the group the Montana and Connecticut amendments moved back into scope, because the surviving entity-level carve-outs in those states are written for chartered banks, credit unions, insurers, and registered advisers rather than for GLBA coverage generally.

How long do you have to respond to a consumer data request?

Forty-five days from receipt in all five states, with one extension of up to 45 more days where reasonably necessary, provided you tell the consumer about the extension and the reason within the initial period. Time spent verifying identity runs inside that window rather than pausing it, which is where institutions with no existing request workflow lose the most days. Connecticut, Colorado, Minnesota, Montana, and Oregon also require a consumer appeal process for a denial.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.