Gramm-Leach-Bliley Act (GLBA) for the Notary Signing Agent
Updated: Aug 19
Written by Beth Hathoot
Edited & Updated 08/2026
Ever wondered what the Gramm-Leach-Bliley Act (GLBA) has to do with you as a Notary Signing Agent? When you're handling loan documents filled with sensitive borrower information, understanding how that information should be protected matters.

Chances are you have seen The Gramm-Leach-Bliley Act (GLBA) referenced in your SPW Code of Conduct and the exam you likely took with the NNA as a Notary Signing Agent. I'm guessing you want to know what that has to do with you as a Notary Signing Agent. I promise I'll get to that but first, you should understand exactly what you are dealing with here.
What Is the Gramm-Leach-Bliley Act (GLBA)?
This is also known as the Financial Modernization Act of 1999, a Federal law enacted to control how financial institutions handle individuals' private information. It not only governs when they can share Non-public Personal Information (NPPI) but also how they can share it. Several agencies contribute to the regulations within the act as well as have a role in enforcing those regulations.
Consumer Financial Protection Bureau (CFPB)
Federal Trade Commission (FTC)
Federal Banking Agencies
Federal Regulatory Agencies
State Insurance Oversight Agencies
The Securities Exchange Commission (SEC)
State laws also play a role and can require greater compliance, but not less than what is required by GLBA.
What is considered Non-Public Personal Information (NPPI)?
An individual’s name
Income
Social Security Number
Marital Status
Address
Birth dates
Education level
Employment data
Amount of savings or investments
Loan or deposit balance
Credit and debit card purchases
Account numbers
Consumer credit reports
Where the individual may have an account – what financial institution
Bio-metric Data (Fingerprints)
Geolocation data
Internet and other electronic information
Tax information
Who is regulated by GLBA?
Financial institutions
Non-bank mortgage lenders
Real Estate Appraisers
Loan Brokers
Some Financial or investment advisers
Credit reporting companies
Payday lenders
Debt collectors
Car rental companies
Car Dealers
Courier services
Universities
Tax return preparers and accountants
Banks and Credit Unions
Real Estate Settlement providers, including Title and Escrow and Real Estate closing attorneys
There are two major components of the GLBA
Financial Privacy Rule, this restricts the sharing of NPPI
Safeguards Rule, requires a security plan both as a company policy and Cyber Security policy
It also states that when information is shared with unaffiliated or third parties, that party must handle the information in accordance with GLBA regulations.
Just like the companies we do assignments for, we are subject to the Safeguard Rule;
Ensure the confidentiality and integrity of NPPI
Protect against common cyber-attacks, cyber threats, and attack vectors
Protect against data breaches, data leaks, and unauthorized access to or use of NPPI
Regulations apply to any record containing NPPI whether paper, electronic, or other form
There are other regulations we don’t need to get into here as they don’t apply to us…yet.
Under GLBA, Financial institutions who disclose NPPI to a third-party vendor or service provider (that’s us) must enter into a contractual agreement.
(Which is why we will typically sign an agreement with the companies that we work with).
Non-compliance penalties are steep; $10,000 fine for each violation for individuals and up to 5-yrs in prison.
As Notary Signing Agents, we really need to think twice about how we are handling NPPI received through our loan signings.
The equipment you use is part of protecting the sensitive information entrusted to you. Using your own secure printer and scanner gives you greater control over where loan documents are printed, scanned, stored, and accessed.
If you're building or upgrading your notary office, visit our 2026 Printer and Scanner Buyer's Guides for equipment recommendations and tips for creating a secure, efficient workspace.
Recent GLBA cases brought by the FTC include:
Ascension Data and Analytics. In 2020, the Arlington, Texas, company agreed to an undisclosed financial settlement after a vendor, OpticsML, was found to have stored customer financial information in plain text in insecure cloud storage.
PayPal. The online payment processor agreed to pay $175,000 to the state of Texas in 2018 to settle GLBA and Federal Trade Act violations that compromised data security and privacy of customers using its Venmo peer-to-peer application.
TaxSlayer. Hackers were able to access nearly 9,000 of the
Augusta, Ga., online tax preparer and customer records for several months in 2015. The FTC said it failed to implement a comprehensive security program.
Sources & References
Written by Beth Hathoot for Notary Stars
Originally Published: 02/22/2022
Are You Subscribed?
Don't Miss Important Emails About the Notary Community.
Subscribe to the Notary Stars Newsletter Today!




Comments