Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Analyzing How Financial Institutions are Treated in Proposed State Privacy Laws

By David Stauss [Former Attorney] & Marci Kawski on February 28, 2019
Email this postTweet this postLike this postShare this post on LinkedIn
privacy computer

One of the myriad of issues arising from the California Consumer Privacy Act (CCPA) is the extent to which financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) must comply with the CCPA’s requirements in light of Section 1798.145(e), which provides that the CCPA “shall not apply to personal information collected, processed, sold, or disclosed pursuant to [the GLBA], and implementing regulations.” Because the CCPA’s definition of “personal information” is broader than the GLBA’s definition of “nonpublic personal information,” financial institutions have been faced with the daunting task of not only data mapping but also classifying that data based on whether it is subject to the GLBA. 

To add to that task, over the last two months, consumer privacy legislation has been proposed in a number of other state legislatures, including Hawaii, Maryland, Massachusetts, New Jersey, New Mexico, Nevada, Rhode Island and Washington. Although that proposed legislation is, of course, subject to change or outright legislative failure, the proposed bills notably do not take a consistent approach with respect to GLBA-regulated financial institutions. This potential for divergent treatment is of particular concern given that many financial institutions are already building their CCPA compliance programs due to the CCPA’s twelve-month look-back period having begun on January 1, 2019.

In the below chart, we analyze how a number of proposed state laws have approached the GLBA carve-out issue (if at all). For proper context, we also identify whether those proposed laws grant consumers the right to access their personal information, the right to be forgotten, and the right to opt-out of a business’s transfer of the consumer’s personal information to third parties. Although not discussed in the chart, the definitions of “personal information” or “personal data” in all of the proposed statutes are broad enough to be inclusive of “nonpublic personal information” as defined in 15 U.S.C. § 6809(4). After the chart, we provide some analysis and takeaways.

State Right to Access Right to be Forgotten Right to Opt-Out of Transfers of PI to Third Parties GLBA Carve-Out Language
Hawaii
(SB 418)
Yes. Yes. Yes. No.
Maryland
(SB 613)
Yes. Yes. Yes. “This subtitle does not apply to . . . personal information collected, processed, sold or disclosed under the federal [GLBA] and implementing regulations.”
Massachusetts (Bill SD.341) Yes. Yes. Yes. “This chapter shall not apply to . . . personal information collected, processed, sold, or disclosed pursuant to the federal [GLBA] and implementing regulations.”
New Jersey
(AB 4902)
No. No. Yes. No.
New Mexico (SB 176) Yes. Yes. Yes. “The Consumer Information Privacy Act shall not apply to information that is collected or used pursuant to state or federal law if the application is in conflict with that law. The office of the attorney general may promulgate rules to clarify when the application of the Consumer Information Privacy Act is in conflict with state or federal law.”
Nevada
(SB 220)
No. No. Yes. No.
Rhode Island (SB 234) Yes. Yes. Yes. No.
Washington (SB 5376) Yes. Yes. Yes. “This chapter does not apply to . . . personal data collected, processed, sold, or disclosed pursuant to [GLBA], and implementing regulations, if the collection, processing, sale, or disclosure is in compliance with that law.”

Perhaps the most notable takeaway is that none of the proposed laws provides a complete carve-out for GLBA-regulated entities. Rather, at most, Maryland, Massachusetts, and Washington are consistent with the CCPA insofar as they carve-out personal information that is subject to the CCPA but not all personal information held by GLBA-regulated entities.

Yet, financial institutions will certainly note that the proposed legislation in Hawaii, New Jersey, Nevada and Rhode Island does not currently contain any GLBA carve-outs. The lack of carve-outs is less concerning with respect to the New Jersey and Nevada legislation because those bills only would provide consumers with the right to opt-out of the transfer of personal information to third parties.

In contrast, Hawaii and Rhode Island would also grant consumers the right to access their personal information and to have it deleted. Those rights would create an additional compliance burden on financial institutions. For example, a business responding to a California resident’s verifiable request to access her personal information would be able to exclude nonpublic personal information. However, that same business would have to include that information when responding to a Hawaii or Rhode Island resident’s request.

Finally, New Mexico’s approach is reminiscent of the CCPA’s original carve-out language before it was amended. Specifically, the CCPA originally provided that it would not apply “to personal information collected, processed, sold, or disclosed pursuant to the [GLBA], and implementing regulations, if it is in conflict with that law.” The inclusion of the phrase “if it is in conflict with that law” led to widespread confusion and it was removed when the CCPA was amended in Senate Bill 1121. New Mexico has apparently tried to address this confusion by proposing to charge the New Mexico Attorney General’s office with issuing guidance.

In the end, it is anyone’s guess whether these proposed bills will become law. However, what does appear inevitable is that states other than California will enact consumer privacy legislation. Because of that inevitability, financial institutions should strongly consider building scalable and repeatable compliance programs that can adapt to new state privacy laws. For more information on privacy-related legislation, contact David Stauss or Marci Kawski.

Photo of David Stauss [Former Attorney] David Stauss [Former Attorney]

Formerly with Husch Blackwell, David routinely counseled clients on complying with privacy laws such as the EU’s General Data Protection Regulation, the California Consumer Privacy Act, the Colorado Privacy Act, and other state privacy laws.

Email
Photo of Marci Kawski Marci Kawski

Marci represents installment lenders, auto finance companies, payday and short-term lenders, online lenders, credit unions, and banks when faced with regulatory issues. She provides practical advice to clients to ensure they comply with the myriad laws governing their businesses. Marci’s skills extend to…

Marci represents installment lenders, auto finance companies, payday and short-term lenders, online lenders, credit unions, and banks when faced with regulatory issues. She provides practical advice to clients to ensure they comply with the myriad laws governing their businesses. Marci’s skills extend to all aspects of consumer finance litigation: discovery, dispositive motion practice, mediation, negotiation of settlement agreements, trial and appeal. Her litigation experience informs her counsel to clients hoping to avoid regulatory issues. Credit unions and other financial institutions also turn to Marci to prepare and review third-party and vendor contracts.

Read more about Marci KawskiEmailMarci's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Byte Back
  • Organization:
    Husch Blackwell LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo