Financial Privacy Landscape and Regulators
Last reviewed:
U.S. financial privacy is governed mainly by the FCRA (1970), GLBA (1999), and the Dodd-Frank Act (2010), which created the CFPB. Financial institutions face both restrictions on use/disclosure and mandatory disclosure duties under anti-money-laundering laws.
Banking and financial records have long been treated as confidential, both to encourage honest borrower reporting and to protect against thieves and fraudsters. This chapter covers how financial firms may collect, use and disclose personal information, plus the rules requiring them to disclose information (anti-money-laundering laws).
The chapter proceeds through the FCRA (1970, updated by FACTA in 2003), the privacy and security provisions of GLBA (1999), and the Dodd-Frank Act (2010), which created the CFPB. The CFPB now has rulemaking authority for the FCRA/FACTA and most GLBA institutions, sharing enforcement with the FTC and banking regulators.
FCRA/FACTA governs credit reporting; GLBA governs financial-institution data handling; Dodd-Frank created the regulator (CFPB) and added the "abusive" enforcement standard.
Key terms - quick answers
What is “FCRA”?
What is “FACTA”?
What is “GLBA”?
What is “Dodd-Frank Act”?
Keep going - free
Every study note on this site is free. So are these: