Compliance/Global/GLBA
Three instruments: sixteen leave evidence in the file.
The Act makes every financial institution responsible for the security and confidentiality of customers' nonpublic personal information. Vaultize adds records that stay with the file.
- Safeguards Rule, 16 CFR 314
- FTC notification since 13 May 2024
- Capability mapping, not legal advice
6801(a)Statute, 15 U.S.C. 6801
It is the policy of the Congress that each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers' nonpublic personal information.
Discover & Classify · Vaultize Seal
USC
Statute, 15 U.S.C. 6801
1 of 9
- 6801
- 6802
- 6803
- 6804
- 6805
- 6806
- 6807
- 6808
- 6809
314
Safeguards Rule, 16 CFR 314
2 of 6
- 314.1
- 314.2
- 314.3
- 314.4
- 314.5
- 314.6
313
Privacy Rule, 16 CFR 313
0 of 18
- 313.1
- 313.2
- 313.3
- 313.4
- 313.5
- 313.6
- 313.7
- 313.8
- 313.9
- 313.10
- 313.11
- 313.12
- 313.13
- 313.14
- 313.15
- 313.16
- 313.17
- 313.18
The answer in 30 seconds
Vaultize adds file-level records to sixteen provisions: the statute's affirmative obligation and standards duty, and twelve of the Safeguards Rule's elements for access, encryption, disposal, monitoring, service providers, incident response and FTC notification. The written information security program, the Qualified Individual, the risk assessment, penetration testing, workforce training and the consumer notice-and-opt-out process under the Privacy Rule sit outside a governed file, with the financial institution.
The instruments in one view
Three instruments. Thirty-three sections. Where file evidence lands.
GLBA is not one certification. The statute sets the obligation, the Safeguards Rule sets the technical duties, and the Privacy Rule sets the notice and opt-out process. All three are shown together below. The Safeguards Rule is where a governed file's evidence concentrates. Entities under CFPB jurisdiction follow the same privacy provisions under Regulation P, 12 CFR Part 1016, rather than Part 313.
USC
Statute, 15 U.S.C. 6801
Sections 6801 to 6809. The policy obligation to protect customer information, the limits on disclosing it to nonaffiliated third parties, the notice and enforcement provisions, and the definitions that carry through the Subtitle.
Outcomes the file can evidence
- How Vaultize contributes
- Encryption sealed into the document with customer-controlled keys, and the classification and per-access records around it, are the kind of continuing technical measure the affirmative obligation in section 6801 points to. Vaultize does not decide what counts as nonpublic personal information or discharge the obligation itself.
- Evidence to retain
- Discovery inventory. Classification history. Encryption on the file with customer-controlled keys. Per-access records.
Provision by provision
What each provision asks. What the file can answer.
Wording is quoted from 15 U.S.C. 6801 to 6809 and from 16 CFR Part 314, current as of 3 September 2026 per the eCFR. Longer provisions are excerpted. Each row is a capability mapping, not legal advice. Read the Act and the Rules and take advice on applicability, roles and technical implementation.
Using this page
Where these rows fit in a GLBA programme.
The Safeguards Rule's 2021 amendments carried a compliance deadline of 9 June 2023. The FTC notification duty at 314.4(j) has applied since 13 May 2024. The rows above are evidence for the obligations that touch documents.
- 1
Confirm financial institution status
Sections 6809 and 314.2. Whether the entity is a "financial institution" under the Act and the Rule, and the definitions that follow from that status.
- 2
Build the information security program
Sections 314.3 and 314.4(a) to (b). The written programme, the Qualified Individual, and the risk assessment it rests on.
- 3
Apply the safeguards
Section 314.4(c). Access controls, encryption, multi-factor authentication, secure disposal and monitoring and logging. These rows belong here.
Bring the sixteen rows above as evidence of the safeguards section 314.4(c) requires and the objectives section 314.3 sets.
- 4
Monitor, oversee providers and respond to incidents
Section 314.4(d) to (h). Testing and monitoring, service-provider oversight, and the written incident response plan.
- 5
Notify the FTC
Section 314.4(j). Notification to the Federal Trade Commission when a notification event involves at least 500 consumers.
Responsibility boundary
Controls support compliance. They are not legal advice.
Vaultize contributes technical measures and evidence for customer information held in documents. It does not write the information security program, designate a Qualified Individual, perform the risk assessment, run penetration testing or vulnerability assessments, train personnel, select or oversee service providers, hold the incident response plan, or notify the Federal Trade Commission. It does not manage the consumer notices and opt-out rights the Privacy Rule requires. This page is a capability mapping, not legal advice. Read the Act and the Rules and take qualified advice before relying on this page.
“You shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of any customer information at issue.”
16 CFR 314.3(a), FTC Safeguards Rule
Official references
Read the source before relying on the mapping.
Section and rule wording comes from the first two items. Longer provisions are excerpted.
- 15 U.S.C. 6801 (Gramm-Leach-Bliley Act, Title V, Subtitle A)United States Code on govinfo, published by the Government Publishing Office. Sections 6801 to 6809 are quoted or cited on this page.
- 16 CFR Part 314 (FTC Safeguards Rule)Electronic Code of Federal Regulations, current as of 3 September 2026. Every Safeguards Rule provision quoted on this page is from it.
- FTC: The Safeguards Rule, what your business needs to knowFTC guidance on the Safeguards Rule, including the 9 June 2023 compliance deadline and the May 2024 notification requirement.
A practical next step
Bring one document that carries customer information.
We will show which provisions the governed document can evidence today. We will name the owner responsible for the rest.
