Tightens GLBA privacy rules: adds data‑minimization, new disclosure/deletion rights, opt‑in for sensitive data, limits on aggregators' credential use, expanded notices, and federal preemption.
Official title: To make improvements to title V of the Gramm-Leach-Bliley Act, and for other purposes.
Introduced April 21, 2026 by Bill Huizenga · Last progress April 21, 2026
The bill creates a stronger, uniform federal privacy regime that gives consumers clearer control and explicit protections for sensitive financial data, but does so at the cost of increased compliance costs, potential operational frictions, gaps for some third parties, and the loss of stronger state-level privacy options.
Consumers nationwide gain a single, uniform federal privacy standard for financial nonpublic personal information, reducing state-to-state variation and making rights more consistent.
Consumers receive stronger transparency and control: clearer affirmative consent, rights to access copies of nonpublic personal information, opt-outs, deletion requests (with narrow exceptions), and improved disclosure content (including AI use, retention, cross-border processing).
Sensitive data (access credentials, biometrics, precise geolocation) is explicitly treated as nonpublic or sensitive, giving consumers stronger protection against misuse of high-risk data elements.
Financial institutions, data aggregators, and payment providers will incur significant compliance and implementation costs (systems, verification, deletion processes, updated disclosures and consent flows), which may be passed on to customers or strain smaller firms.
Consumers in states that currently have stronger privacy laws may lose protections because states cannot adopt rules that exceed the federal floor, potentially weakening rights for those residents.
Data minimization, deletion requirements, and tighter limits on credential/biometric use could complicate fraud prevention, compliance with other recordkeeping laws, and some legitimate operational uses, creating legal and operational friction for firms and potential service delays for customers.
Based on analysis of 4 sections of legislative text.
Makes major changes to the Gramm‑Leach‑Bliley Act to strengthen consumer privacy protections for financial data. It adds new data‑minimization duties, expanded disclosure and deletion rights for customers and former customers, requires opt‑in consent for sensitive nonpublic personal information, limits use of consumer access credentials by data aggregators, expands required privacy notice content (including AI, retention, purposes, and cross‑border processing), and updates definitions to cover access credentials, biometric and precise geolocation data, and financial data aggregators. It also requires regulators to consider effects on smaller financial institutions when writing rules, and replaces the prior state‑law approach with an explicit federal preemption that bars States from imposing consumer data privacy/security requirements that differ from the subtitle (while preserving a limited role for State insurance authorities). Several provisions phase in over 1–2 years and agencies must update model forms with a temporary safe harbor after those updates.