Compliance research

GLBA Privacy Notices and Regulation P: What an Insurance Agency Must Tell Customers

A sourced review of the Gramm-Leach-Bliley Act privacy provisions and the FTC's Regulation P, focused on initial notices, opt-out rights, exceptions, and how privacy notice duties differ from the Safeguards Rule.

Published: September 18, 2026 · InsuranceYo Research

GLBA Privacy Notices and Regulation P: What an Insurance Agency Must Tell Customers research illustration

Research question

What does the Gramm-Leach-Bliley Act privacy framework require an insurance agency to tell its customers, and how does the privacy notice duty differ from the data security duty that many agencies already track?

The question matters because agencies often group their federal privacy obligations under a single label and assume the Safeguards Rule covers everything. It does not. The Gramm-Leach-Bliley Act has a separate privacy notice requirement, implemented for many institutions by the Federal Trade Commission's Regulation P, and it operates on a different logic from the information security rules. This paper reviews the primary sources. It is not legal advice.

Method

This is a desk review of the following sources:

  1. The Federal Trade Commission's Gramm-Leach-Bliley Act topic page, which describes which companies the law covers and what it requires.
  2. The FTC's business guidance, "How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act," which describes the privacy notice and opt-out framework.
  3. The Gramm-Leach-Bliley Act, 15 U.S.C. 6801 through 6809, with particular attention to the obligations at 15 U.S.C. 6802 and 6803.
  4. Regulation P, 16 CFR Part 313, as published in the Electronic Code of Federal Regulations.
  5. The FTC's Safeguards Rule material at 16 CFR Part 314 for comparison, because that rule is the one agencies most often confuse with the privacy rule.

The FTC pages were read in full. The statutory and regulatory provisions were reviewed at the section level. No agency notice, privacy policy, or vendor contract was examined. Evidence checked September 18, 2026.

Evidence

The law reaches insurance

The FTC states that the Gramm-Leach-Bliley Act requires financial institutions, described as companies that offer consumers financial products or services such as loans, financial or investment advice, or insurance, to explain their information-sharing practices to their customers and to safeguard sensitive data. That sentence contains both halves of the framework: the privacy notice duty and the security duty. Insurance is named as a covered category.

Source fact: The FTC describes insurance as a financial product for purposes of the law, so an insurance agency should treat the privacy obligations as potentially applicable rather than assume the law is limited to banks.

The privacy notice and opt-out framework

The FTC states that financial institutions covered by the law must tell their customers about their information-sharing practices and explain the customers' right to opt out if they do not want their information shared with certain third parties. The implementing rule that the FTC points to is the Privacy of Consumer Financial Information Rule, which appears at 16 CFR Part 313, commonly called Regulation P. The FTC also publishes a model privacy form under Part 313 that institutions may use.

The framework therefore has two customer-facing elements. The first is a notice describing what information the institution collects and how it shares it. The second is an opt-out right for certain sharing with nonaffiliated third parties.

Source fact: The privacy rule is about disclosure to the customer and the customer's choice, not about firewalls or encryption.

What the notice describes

The privacy notice describes the institution's policies and practices with respect to nonpublic personal information. That term is defined in the statute and rule and generally covers personally identifiable financial information that a consumer provides to a financial institution, that the institution obtains about a consumer in connection with providing a financial product or service, or that the institution otherwise obtains about a consumer. The notice describes categories of information collected, categories of affiliates and nonaffiliated third parties to whom the information may be disclosed, and the policies and practices for protecting the information.

Source fact: The notice is a description of practices, so an agency should write it to match what it actually does.

The opt-out right and its exceptions

The statute at 15 U.S.C. 6802 generally prohibits a financial institution from disclosing nonpublic personal information to a nonaffiliated third party unless the institution has provided the required notice and the consumer has not opted out, subject to statutory exceptions. The exceptions at 15 U.S.C. 6802(e) cover common operational situations, such as disclosures necessary to effect, administer, or enforce a transaction the consumer requested, disclosures with the consumer's consent, disclosures to protect against fraud or unauthorized transactions, and disclosures required by law.

Source fact: The opt-out right applies to certain third-party sharing, and the statutory exceptions matter for routine insurance operations. The exceptions should be read against the specific sharing in question.

Regulation P and the changing annual notice requirement

Regulation P at 16 CFR Part 313 implements the statute for institutions subject to FTC jurisdiction. The rule addresses initial notices, annual notices, and the circumstances under which an institution may not need to deliver an annual notice. The FTC's guidance describes the general framework, and the rule text governs the details. The practical point for an agency is that the annual notice obligation is not unconditional. Under changes made in 2015, an institution may avoid an annual notice in specified circumstances, including where it shares nonpublic personal information only in ways that do not trigger the opt-out right and it has not changed its policies and practices from the most recent disclosure.

Source fact: The annual notice question is conditional. An agency should be able to state which condition applies to it rather than assume an annual mailing is required or not required.

How Regulation P differs from the Safeguards Rule

The Safeguards Rule at 16 CFR Part 314 also implements the Gramm-Leach-Bliley Act, but it addresses information security. It requires covered institutions to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards. The FTC's separate Safeguards Rule materials describe that program, including the designation of a Qualified Individual, a written risk assessment, access controls, encryption, multi-factor authentication, service provider oversight, and incident response.

Regulation P and the Safeguards Rule share a statutory parent, but they impose different obligations. Regulation P asks what the institution tells customers and whether it gives them a choice. The Safeguards Rule asks how the institution protects the information. An agency can satisfy one and fail the other.

Source fact: The two rules are distinct. A privacy notice does not secure data, and a security program does not discharge the notice or opt-out obligations.

State insurance privacy regulation

Because insurance is regulated primarily by the states, the FTC framework is not the only source of privacy obligations. State insurance regulators have adopted privacy regulations modeled on the NAIC's privacy framework, and those state rules can impose notice, authorization, and opt-out requirements that differ from Regulation P. The FTC's authority and a state insurance regulator's authority can both be relevant depending on the entity and activity.

Source fact: An agency operating in multiple states should confirm the privacy requirements of each state insurance regulator, not only the federal rule.

Findings

Finding 1: Privacy notices and security programs are separate duties. The Gramm-Leach-Bliley Act creates both, and the FTC implements them in different rules.

Finding 2: The privacy notice describes practices. Its accuracy depends on the agency knowing what it actually shares and with whom.

Finding 3: The opt-out right is real but bounded. It applies to certain sharing with nonaffiliated third parties and is subject to statutory exceptions.

Finding 4: The annual notice is conditional. An agency should identify the condition that applies rather than default to a mailing or to silence.

Finding 5: State insurance privacy rules can add requirements. Federal compliance is a floor.

Interpretation: what this means for an insurance agency using a virtual assistant

The following is the author's interpretation, not statutory text.

  • An agency that hands client data to a service provider has changed its information-sharing facts. The privacy notice should describe those facts accurately, and the arrangement should be consistent with the agency's opt-out statements and exceptions.
  • Virtual assistants and staffing providers may be service providers rather than nonaffiliated third parties for some purposes, but that characterization depends on the relationship and should be confirmed rather than assumed.
  • The most common practical gap is drift: the notice describes one set of practices, and operations evolve to another. A periodic review keeps the notice honest.
  • Because the privacy duty and the security duty are separate, an agency should not treat a privacy policy update as a substitute for a security program, or the reverse.

Operational implications

These are proposed steps derived from the sources, not a legal checklist.

  1. Separate the two workstreams. Maintain the privacy notice and opt-out process independently from the information security program.
  2. Map actual sharing. List the categories of nonpublic personal information the agency collects, the affiliates and nonaffiliated third parties that receive it, and the purpose of each disclosure.
  3. Confirm the notice describes the map. Update the notice when practices change, and keep a dated record of each version.
  4. Document the opt-out process and the exception the agency relies on for each routine disclosure.
  5. Confirm the annual notice position. Identify whether the agency meets the condition to omit the annual notice, or deliver it.
  6. Address service provider arrangements in the notice and in the vendor relationship, and coordinate with the security program's service provider oversight.
  7. Confirm state privacy rules for each state where the agency operates.
  8. Confirm with counsel. Definitions, exceptions, and state rules are fact-specific.

Limitations

  • Not legal advice. This paper summarizes public sources. It does not determine whether any agency, notice, or sharing practice complies.
  • Rule details not exhaustively reviewed. Regulation P contains definitions, timing rules, and model form provisions that are not reproduced here. The rule text controls.
  • State law not surveyed. State insurance privacy regulations and state financial privacy laws vary and were not reviewed state by state.
  • Definitions are consequential. Whether a recipient is an affiliate, a nonaffiliated third party, or a service provider changes the analysis, and that determination depends on the facts.
  • No facts. No agency notice, sharing arrangement, or vendor contract was examined.

Practical conclusion

The Gramm-Leach-Bliley Act imposes two distinct customer-facing and protective duties on covered financial institutions, including insurance businesses. Regulation P requires an accurate description of information-sharing practices and an opt-out for certain sharing with nonaffiliated third parties, subject to exceptions, while the Safeguards Rule requires an information security program. For an agency delegating client data work to a virtual assistant, the practical response is to map actual sharing, keep the privacy notice accurate and current, document the opt-out process and any exception relied on, confirm the annual notice position, and check the state insurance privacy rules that apply. Because these determinations are fact-specific, the agency should confirm them with qualified counsel rather than rely on a single federal template.

Sources

  1. Federal Trade Commission, Gramm-Leach-Bliley Act (topic page). https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act
  2. Federal Trade Commission, How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act. https://www.ftc.gov/business-guidance/resources/how-comply-privacy-consumer-financial-information-rule-gramm-leach-bliley-act
  3. Gramm-Leach-Bliley Act, 15 U.S.C. 6801 through 6809 (disclosure obligations at 15 U.S.C. 6802; annual notice provision at 15 U.S.C. 6803). https://www.law.cornell.edu/uscode/text/15/6801
  4. Regulation P, Privacy of Consumer Financial Information, 16 CFR Part 313 (including the model privacy form). https://www.ecfr.gov/current/title-16/part-313
  5. Federal Trade Commission, Safeguards Rule, 16 CFR Part 314 (for contrast with the privacy notice duty). https://www.ftc.gov/legal-library/browse/rules/safeguards-rule

Related research