HR8398-119

In Committee

Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act

119th Congress Introduced Apr 21, 2026

Summary

What This Bill Does

The GUARD Financial Data Act amends the Gramm-Leach-Bliley Act to tighten financial privacy rules for nonpublic personal information. It requires financial institutions to limit the collection or disclosure of nonpublic personal information to what is adequate, relevant, and reasonably necessary for each collection or disclosure purpose, while preserving existing disclosures required by GLBA, section 1033 of the Consumer Financial Protection Act, the Fair Credit Reporting Act, regulators, self-regulatory organizations, and other law. The data-minimization provision takes effect two years after enactment.

The bill regulates use of consumer access credentials by financial data aggregators and nonaffiliated third parties. Before collecting or using credentials to access a consumer's account or obtain electronic nonpublic personal information from a financial institution, those entities must give a clear and conspicuous disclosure explaining how the credentials will be used, whether credentials will be disclosed onward, the privacy and security risks, and their privacy and security practices. The consumer must be given an opt-out opportunity, and a financial institution may not deny a disclosure request made with credentials if the consumer received the disclosure and opt-out opportunity. The credential-use rules take effect one year after enactment and remain subject to section 1033 open-banking requirements.

The bill expands GLBA privacy notices. Financial institutions must describe purposes for collecting and disclosing nonpublic personal information, retention practices, artificial-intelligence use in data collection or processing, whether information is processed, retained, or disclosed in a covered nation, opt-out procedures, how customers can get a copy of the privacy disclosure, and how current or former customers can request disclosure or deletion under new section 503A. The GLBA agencies must consult Federal functional regulators to update the model privacy notice form. During the two years after those updates are finalized, a financial institution is treated as compliant if it uses the model form in effect on enactment. Financial institutions must also provide a copy of the privacy disclosure to a customer upon request.

New section 503A gives customers and former customers a right to request disclosure of nonpublic personal information held by a financial institution and a list of affiliate or nonaffiliated third-party categories that received it, subject to legal exceptions. Former customers may request deletion of their nonpublic personal information, subject to exceptions for ongoing legal retention, consumer reporting agency activity under the Fair Credit Reporting Act, dispute response, or other law. Financial institutions must verify former-customer identity before deletion, respond without undue delay and within 45 days, may extend once for another 45 days with notice, must allow two free deletion requests per year, may charge or decline later requests if the former customer does not consent to a fee, and must provide an appeal process with a 60-day response deadline and a complaint route to the proper enforcement agency. Section 503A takes effect two years after enactment.

The bill requires GLBA rulemaking agencies to account for the resource, technical, personnel, and compliance-cost constraints of financial institutions with $15 billion or less in assets when prescribing regulations, and to adjust that threshold for GDP growth starting April 1, 2031, and every five years after that. It also rewrites GLBA's relation-to-state-law provision to preempt state consumer data privacy or security requirements for covered nonpublic personal information and financial institutions, while preserving state insurance authority enforcement and regulations that are consistent, comparable, and not more restrictive than federal GLBA regulations.

The bill updates definitions. It expands nonpublic personal information to include access credentials and, for financial institutions engaging in financial activities, biometric data and precise geolocation data. It defines access credentials, artificial intelligence, biometric data, consent, covered nation, customer, customer relationship, financial data aggregator, former customer, precise geolocation data, self-regulatory organization, sensitive nonpublic personal information, and State. The financial data aggregator definition excludes consumer reporting agencies acting under the Fair Credit Reporting Act, attorneys, accountants, investment advisers, certain payment processors, and self-regulatory organizations in specified capacities.

Who Benefits and How

Financial consumers benefit because the bill limits unnecessary collection or disclosure of their financial data, expands privacy notices, requires transparency before access credentials are used, creates disclosure and deletion request rights, requires identity verification before deletion, and adds appeal and complaint routes. Former financial customers benefit from deletion rights and response deadlines. Small financial institutions benefit because federal rulemaking agencies must consider their compliance constraints and adjust the small-institution threshold over time. Financial institutions also benefit from federal preemption of divergent state privacy and security requirements. State insurance authorities retain enforcement and regulatory authority when their rules are consistent with federal GLBA regulations.

Who Bears the Burden and How

Financial institutions bear compliance burdens from data minimization, expanded privacy notices, customer-requested disclosure copies, section 503A disclosure and deletion workflows, identity verification, response deadlines, appeals, and complaint routing. Financial data aggregators and nonaffiliated data recipients bear new notice and opt-out burdens before using consumer access credentials. Federal GLBA agencies and Federal functional regulators must update model forms and consider small-institution impacts in rulemaking. State privacy regulators lose authority where state data privacy or security requirements are preempted. Consumers in states with stricter financial privacy laws may lose protections that exceed federal GLBA standards.

Key Provisions

  • Requires financial institutions to minimize collection or disclosure of nonpublic personal information to what is adequate, relevant, and reasonably necessary.
  • Requires financial data aggregators and nonaffiliated third parties to give credential-use disclosures and opt-out opportunities before using consumer access credentials.
  • Expands GLBA privacy notices to cover collection purposes, retention, artificial intelligence, covered-nation processing, opt-out procedures, disclosure-copy requests, and section 503A disclosure or deletion rights.
  • Creates section 503A rights for current customers to receive nonpublic personal information and for former customers to request deletion, with verification, response, fee, appeal, and complaint procedures.
  • Requires regulators to consider compliance constraints for financial institutions with $15 billion or less in assets and to adjust that threshold every five years after April 1, 2031.
  • Preempts state consumer data privacy or security requirements for GLBA-covered nonpublic personal information and financial institutions while preserving consistent state insurance authority.
  • Adds definitions covering access credentials, artificial intelligence, biometric data, consent, covered nations, financial data aggregators, former customers, precise geolocation data, self-regulatory organizations, sensitive data, and States.

Evidence Chain:

This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.

At a Glance

What This Bill Does

The bill amends Gramm-Leach-Bliley Act financial privacy rules to require data minimization, expanded consumer notices, credential-use disclosures, consumer access and deletion rights, small-institution rulemaking consideration, federal preemption of state privacy rules, and updated definitions for financial data aggregators and sensitive financial data.

Key Policy Areas

Financial Services, Consumer Protection, Privacy, Technology, Government Operations

Primary Purpose

The bill amends Gramm-Leach-Bliley Act financial privacy rules to require data minimization, expanded consumer notices, credential-use disclosures, consumer access and deletion rights, small-institution rulemaking consideration, federal preemption of state privacy rules, and updated definitions for financial data aggregators and sensitive financial data.

Policy Domains

Financial Services Consumer Protection Privacy Technology Government Operations

Expanded GLBA definitions for data aggregators and sensitive financial data

Identified Gains
  • Financial consumers
  • Consumer reporting agencies
  • Payment processors
  • Self-regulatory organizations
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: ih
Payment processors:
Financial consumers:
Consumer reporting agencies:
Self-regulatory organizations:
Identified Costs
  • Financial institutions subject to GLBA
  • Financial data aggregators
  • Firms using biometric financial data
  • Firms using geolocation financial data
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: ih
Financial data aggregators:
Firms using biometric financial data:
Financial institutions subject to GLBA:
Firms using geolocation financial data:

Small-institution rulemaking consideration and federal preemption of state privacy laws

Identified Gains
  • Small financial institutions
  • Financial institutions subject to GLBA
  • State insurance authorities
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: ih
State insurance authorities: ,
Small financial institutions:
Financial institutions subject to GLBA: ,
Identified Costs
  • Federal GLBA rulemaking agencies
  • State privacy regulators
  • Consumers in states with stricter privacy laws
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: ih
State privacy regulators: ,
Federal GLBA rulemaking agencies:
Consumers in states with stricter privacy laws: ,

GLBA data minimization, credential use, notices, and consumer disclosure/deletion rights

Identified Gains
  • Financial consumers
  • Former financial customers
  • Consumers sharing access credentials
  • Consumer reporting agencies
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: ih
Financial consumers: , ,
Former financial customers: ,
Consumer reporting agencies: ,
Consumers sharing access credentials:
Identified Costs
  • Financial institutions subject to GLBA
  • Financial data aggregators
  • Nonaffiliated financial data recipients
  • Federal GLBA rulemaking agencies
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: ih
Financial data aggregators: ,
Federal GLBA rulemaking agencies:
Financial institutions subject to GLBA: , , ,
Nonaffiliated financial data recipients: ,

Legislative Progress

In Committee
Introduced Committee Passed
Apr 21, 2026

Referred to the House Committee on Financial Services.

Apr 21, 2026

Introduced in House

Apr 21, 2026

Mr. Huizenga (for himself, Mr. Barr, Mr. Steil, and Mr. …

Stakeholder Effects

cui bono?

How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.

Financial Services
19 mentions across 10 clauses
+5 positive -12 negative ?2 uncertain

Financial data aggregators, Financial institutions covered by federal privacy rules, Financial institutions handling expanded personal information

Financial institutions subject to GLBA faces effects in multiple directions

Positive-direction: Financial institutions covered by federal privacy rules, Financial institutions using current model form, Self-regulatory organizations receiving member data, Small financial institutions

Negative-direction: Financial data aggregators, Financial institutions handling expanded personal information, Financial institutions handling section 503A requests, Financial institutions issuing privacy notices, Financial institutions operating deletion workflows, Financial institutions receiving credential-based requests, Financial institutions responding to privacy-disclosure requests, Firms using geolocation financial data, Nonaffiliated financial data recipients

Consumers
11 mentions across 9 clauses
+9 positive -2 negative

Consumers in states with stricter privacy laws, Consumers sharing access credentials, Current financial customers requesting data disclosure

Positive-direction: Consumers sharing access credentials, Current financial customers requesting data disclosure, Current financial customers using disclosure rights, Financial consumers, Financial consumers receiving privacy notices, Financial consumers with sensitive data, Financial customers requesting privacy disclosures, Former financial customers requesting data deletion, Former financial customers using deletion rights

Negative-direction: Consumers in states with stricter privacy laws

Federal Financial Regulators
6 mentions across 5 clauses
-5 negative ?1 uncertain

Federal GLBA rulemaking agencies, Federal functional regulators, Financial privacy enforcement agencies

Credit Bureaus
3 mentions across 3 clauses
+2 positive ?1 uncertain

Consumer reporting agencies, Consumer reporting agencies acting under FCRA, Consumer reporting agencies retaining FCRA data

State & Local Government
2 mentions across 2 clauses
+2 positive

State privacy regulators

Technology
1 mention across 1 clause
-1 negative

Firms using biometric financial data

Payment Processing
1 mention across 1 clause
+1 positive

Payment processors outside financial-institution status

Federal Administration
1 mention across 1 clause
?1 uncertain

Department of Commerce economic data programs

10/14
sections analyzed
Full impact breakdown

Bill Structure & Actor Mappings

Who is "The Secretary" in each section?

Domains
Financial Services Consumer Protection Privacy
Actor Mappings
"consumers"
→ Financial consumers
"aggregators"
→ Financial data aggregators
"third_parties"
→ Nonaffiliated financial data recipients
"former_customers"
→ Former financial customers
"financial_institutions"
→ Financial institutions subject to GLBA
Domains
Financial Services Government Operations
Actor Mappings
"glba_agencies"
→ Federal GLBA rulemaking agencies
"small_institutions"
→ Small financial institutions
"state_privacy_regulators"
→ State privacy regulators
"state_insurance_authorities"
→ State insurance authorities
Domains
Financial Services Privacy Technology
Actor Mappings
"financial_institutions"
→ Financial institutions subject to GLBA
"financial_data_aggregators"
→ Financial data aggregators
"consumer_reporting_agencies"
→ Consumer reporting agencies
"self_regulatory_organizations"
→ Self-regulatory organizations

Key Definitions

Terms defined in this bill

3 terms
"access credentials" §access_credentials

Personally identifiable nonfinancial information a consumer uses to access a financial account, such as usernames, passwords, PINs, access codes, or security-question answers.

"financial data aggregator" §financial_data_aggregator

A commercial enterprise that receives, processes, or discloses nonpublic personal information to provide products or services used primarily for personal, family, or household purposes, with specified exclusions.

"sensitive nonpublic personal information" §sensitive_nonpublic_personal_information

Financial-activity data that discloses specified traits or status, genetic or biometric data used to identify a consumer, or precise geolocation data.

We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.

Learn more about our methodology