Financial Associations Urge Lawmakers to Update Data Privacy Law for Financial Institutions

As lawmakers consider updating the federal data privacy law for financial institutions, the American Bankers Association and four other banking and credit union associations have weighed in with recommendations to improve the Gramm-Leach-Bliley Act, which was established in 1999. The associations argue that the current law is a carefully calibrated regime that benefits consumers, but needs to be updated to reflect the modern financial services ecosystem.

Key Takeaways:

  • The Gramm-Leach-Bliley Act should clearly preempt state privacy laws to avoid interference with core financial activities that benefit consumers.
  • Any entities subject to the GLBA should be exempt from comprehensive federal consumer privacy laws to maintain a consistent regulatory playing field.
  • The GLBA should continue to be enforced by federal regulators rather than through private litigation.
  • A safe harbor should be created for the sharing of information regarding fraud and scams.
  • The GLBA should be harmonized with Section 1033 of the Dodd-Frank Act to address issues such as liability for data breaches and consumer data subject rights.
  • Lawmakers should reconsider national data breach standards, as complying with 50 state data breach notification requirements plus other territories is overly burdensome on financial institutions.

Statistics:

  • The Gramm-Leach-Bliley Act was established in 1999.
  • The American Bankers Association and four other banking and credit union associations submitted a joint letter to the House Financial Services Committee.
  • 50 state data breach notification requirements plus the District of Columbia and other territories are currently in place.

Sources:

  • Joint letter submitted by the American Bankers Association and four other banking and credit union associations to the House Financial Services Committee.
  • House Financial Services Committee request for public feedback on current federal data privacy law for financial institutions (July).
  • Gramm-Leach-Bliley Act of 1999.
  • Section 1033 of the Dodd-Frank Act.