GLBA (Gramm-Leach-Bliley Act)
The Gramm-Leach-Bliley Act (GLBA) is the federal law requiring financial institutions — including MCA funders and brokers handling sensitive financial information — to safeguard customer data, provide privacy notices, and limit information sharing without consent.
Why This Matters
GLBA applies to MCA actors who collect, store, or share customer financial information — bank statements, credit data, processing volume reports, tax returns. The Safeguards Rule requires written information security programs, employee training, vendor management oversight, and incident response capabilities. The Privacy Rule requires customer-facing privacy notices at relationship initiation and annually thereafter. The 2023 Safeguards Rule update added specific technical controls including encryption, multi-factor authentication, continuous monitoring, and incident response planning.
Frequently Asked Questions
Frequently Asked Questions
Are MCA brokers subject to GLBA?
Yes — any organization significantly engaged in financial activities falls under GLBA, including ISOs and brokers handling merchant financial information. The 2023 Safeguards Rule update broadened technical control obligations and applies to brokers handling sensitive customer financial information.
What's the penalty for GLBA violations?
FTC enforcement actions can include consent orders, mandatory security program implementation, and monetary penalties up to $46,517 per violation (2024 figure). High-profile cases against brokerage and lending firms have included multi-million dollar settlements and 20-year compliance monitoring obligations.