Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act
Summary
What This Bill Does
The GUARD Financial Data Act amends the Gramm-Leach-Bliley Act to tighten financial privacy rules for nonpublic personal information. It requires financial institutions to limit the collection or disclosure of nonpublic personal information to what is adequate, relevant, and reasonably necessary for each collection or disclosure purpose, while preserving existing disclosures required by GLBA, section 1033 of the Consumer Financial Protection Act, the Fair Credit Reporting Act, regulators, self-regulatory organizations, and other law. The data-minimization provision takes effect two years after enactment.
The bill regulates use of consumer access credentials by financial data aggregators and nonaffiliated third parties. Before collecting or using credentials to access a consumer's account or obtain electronic nonpublic personal information from a financial institution, those entities must give a clear and conspicuous disclosure explaining how the credentials will be used, whether credentials will be disclosed onward, the privacy and security risks, and their privacy and security practices. The consumer must be given an opt-out opportunity, and a financial institution may not deny a disclosure request made with credentials if the consumer received the disclosure and opt-out opportunity. The credential-use rules take effect one year after enactment and remain subject to section 1033 open-banking requirements.
The bill expands GLBA privacy notices. Financial institutions must describe purposes for collecting and disclosing nonpublic personal information, retention practices, artificial-intelligence use in data collection or processing, whether information is processed, retained, or disclosed in a covered nation, opt-out procedures, how customers can get a copy of the privacy disclosure, and how current or former customers can request disclosure or deletion under new section 503A. The GLBA agencies must consult Federal functional regulators to update the model privacy notice form. During the two years after those updates are finalized, a financial institution is treated as compliant if it uses the model form in effect on enactment. Financial institutions must also provide a copy of the privacy disclosure to a customer upon request.
New section 503A gives customers and former customers a right to request disclosure of nonpublic personal information held by a financial institution and a list of affiliate or nonaffiliated third-party categories that received it, subject to legal exceptions. Former customers may request deletion of their nonpublic personal information, subject to exceptions for ongoing legal retention, consumer reporting agency activity under the Fair Credit Reporting Act, dispute response, or other law. Financial institutions must verify former-customer identity before deletion, respond without undue delay and within 45 days, may extend once for another 45 days with notice, must allow two free deletion requests per year, may charge or decline later requests if the former customer does not consent to a fee, and must provide an appeal process with a 60-day response deadline and a complaint route to the proper enforcement agency. Section 503A takes effect two years after enactment.
The bill requires GLBA rulemaking agencies to account for the resource, technical, personnel, and compliance-cost constraints of financial institutions with $15 billion or less in assets when prescribing regulations, and to adjust that threshold for GDP growth starting April 1, 2031, and every five years after that. It also rewrites GLBA's relation-to-state-law provision to preempt state consumer data privacy or security requirements for covered nonpublic personal information and financial institutions, while preserving state insurance authority enforcement and regulations that are consistent, comparable, and not more restrictive than federal GLBA regulations.
The bill updates definitions. It expands nonpublic personal information to include access credentials and, for financial institutions engaging in financial activities, biometric data and precise geolocation data. It defines access credentials, artificial intelligence, biometric data, consent, covered nation, customer, customer relationship, financial data aggregator, former customer, precise geolocation data, self-regulatory organization, sensitive nonpublic personal information, and State. The financial data aggregator definition excludes consumer reporting agencies acting under the Fair Credit Reporting Act, attorneys, accountants, investment advisers, certain payment processors, and self-regulatory organizations in specified capacities.
Who Benefits and How
Financial consumers benefit because the bill limits unnecessary collection or disclosure of their financial data, expands privacy notices, requires transparency before access credentials are used, creates disclosure and deletion request rights, requires identity verification before deletion, and adds appeal and complaint routes. Former financial customers benefit from deletion rights and response deadlines. Small financial institutions benefit because federal rulemaking agencies must consider their compliance constraints and adjust the small-institution threshold over time. Financial institutions also benefit from federal preemption of divergent state privacy and security requirements. State insurance authorities retain enforcement and regulatory authority when their rules are consistent with federal GLBA regulations.
Who Bears the Burden and How
Financial institutions bear compliance burdens from data minimization, expanded privacy notices, customer-requested disclosure copies, section 503A disclosure and deletion workflows, identity verification, response deadlines, appeals, and complaint routing. Financial data aggregators and nonaffiliated data recipients bear new notice and opt-out burdens before using consumer access credentials. Federal GLBA agencies and Federal functional regulators must update model forms and consider small-institution impacts in rulemaking. State privacy regulators lose authority where state data privacy or security requirements are preempted. Consumers in states with stricter financial privacy laws may lose protections that exceed federal GLBA standards.
Key Provisions
- Requires financial institutions to minimize collection or disclosure of nonpublic personal information to what is adequate, relevant, and reasonably necessary.
- Requires financial data aggregators and nonaffiliated third parties to give credential-use disclosures and opt-out opportunities before using consumer access credentials.
- Expands GLBA privacy notices to cover collection purposes, retention, artificial intelligence, covered-nation processing, opt-out procedures, disclosure-copy requests, and section 503A disclosure or deletion rights.
- Creates section 503A rights for current customers to receive nonpublic personal information and for former customers to request deletion, with verification, response, fee, appeal, and complaint procedures.
- Requires regulators to consider compliance constraints for financial institutions with $15 billion or less in assets and to adjust that threshold every five years after April 1, 2031.
- Preempts state consumer data privacy or security requirements for GLBA-covered nonpublic personal information and financial institutions while preserving consistent state insurance authority.
- Adds definitions covering access credentials, artificial intelligence, biometric data, consent, covered nations, financial data aggregators, former customers, precise geolocation data, self-regulatory organizations, sensitive data, and States.
Evidence Chain:
This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.
At a Glance
What This Bill Does
The bill amends Gramm-Leach-Bliley Act financial privacy rules to require data minimization, expanded consumer notices, credential-use disclosures, consumer access and deletion rights, small-institution rulemaking consideration, federal preemption of state privacy rules, and updated definitions for financial data aggregators and sensitive financial data.
Key Policy Areas
Financial Services, Consumer Protection, Privacy, Technology, Government Operations
Primary Purpose
The bill amends Gramm-Leach-Bliley Act financial privacy rules to require data minimization, expanded consumer notices, credential-use disclosures, consumer access and deletion rights, small-institution rulemaking consideration, federal preemption of state privacy rules, and updated definitions for financial data aggregators and sensitive financial data.
Policy Domains
Expanded GLBA definitions for data aggregators and sensitive financial data
Identified Gains
- Financial consumers
- Consumer reporting agencies
- Payment processors
- Self-regulatory organizations
Identified Costs
- Financial institutions subject to GLBA
- Financial data aggregators
- Firms using biometric financial data
- Firms using geolocation financial data
Small-institution rulemaking consideration and federal preemption of state privacy laws
Identified Gains
- Small financial institutions
- Financial institutions subject to GLBA
- State insurance authorities
Identified Costs
- Federal GLBA rulemaking agencies
- State privacy regulators
- Consumers in states with stricter privacy laws
GLBA data minimization, credential use, notices, and consumer disclosure/deletion rights
Identified Gains
- Financial consumers
- Former financial customers
- Consumers sharing access credentials
- Consumer reporting agencies
Identified Costs
- Financial institutions subject to GLBA
- Financial data aggregators
- Nonaffiliated financial data recipients
- Federal GLBA rulemaking agencies
Sponsors
Legislative Progress
In CommitteeReferred to the House Committee on Financial Services.
Introduced in House
Mr. Huizenga (for himself, Mr. Barr, Mr. Steil, and Mr. …
Stakeholder Effects
cui bono?How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.
Financial data aggregators, Financial institutions covered by federal privacy rules, Financial institutions handling expanded personal information
Financial institutions subject to GLBA faces effects in multiple directions
Positive-direction: Financial institutions covered by federal privacy rules, Financial institutions using current model form, Self-regulatory organizations receiving member data, Small financial institutions
Negative-direction: Financial data aggregators, Financial institutions handling expanded personal information, Financial institutions handling section 503A requests, Financial institutions issuing privacy notices, Financial institutions operating deletion workflows, Financial institutions receiving credential-based requests, Financial institutions responding to privacy-disclosure requests, Firms using geolocation financial data, Nonaffiliated financial data recipients
Consumers in states with stricter privacy laws, Consumers sharing access credentials, Current financial customers requesting data disclosure
Positive-direction: Consumers sharing access credentials, Current financial customers requesting data disclosure, Current financial customers using disclosure rights, Financial consumers, Financial consumers receiving privacy notices, Financial consumers with sensitive data, Financial customers requesting privacy disclosures, Former financial customers requesting data deletion, Former financial customers using deletion rights
Negative-direction: Consumers in states with stricter privacy laws
Federal GLBA rulemaking agencies, Federal functional regulators, Financial privacy enforcement agencies
Consumer reporting agencies, Consumer reporting agencies acting under FCRA, Consumer reporting agencies retaining FCRA data
Payment processors outside financial-institution status
Department of Commerce economic data programs
Bill Structure & Actor Mappings
Who is "The Secretary" in each section?
- "consumers"
- → Financial consumers
- "aggregators"
- → Financial data aggregators
- "third_parties"
- → Nonaffiliated financial data recipients
- "former_customers"
- → Former financial customers
- "financial_institutions"
- → Financial institutions subject to GLBA
- "glba_agencies"
- → Federal GLBA rulemaking agencies
- "small_institutions"
- → Small financial institutions
- "state_privacy_regulators"
- → State privacy regulators
- "state_insurance_authorities"
- → State insurance authorities
- "financial_institutions"
- → Financial institutions subject to GLBA
- "financial_data_aggregators"
- → Financial data aggregators
- "consumer_reporting_agencies"
- → Consumer reporting agencies
- "self_regulatory_organizations"
- → Self-regulatory organizations
Key Definitions
Terms defined in this bill
Personally identifiable nonfinancial information a consumer uses to access a financial account, such as usernames, passwords, PINs, access codes, or security-question answers.
A commercial enterprise that receives, processes, or discloses nonpublic personal information to provide products or services used primarily for personal, family, or household purposes, with specified exclusions.
Financial-activity data that discloses specified traits or status, genetic or biometric data used to identify a consumer, or precise geolocation data.
We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.
Learn more about our methodology