Sitonce
Country: HK
Show exams for United States Hong Kong
Sign in

Gramm-Leach-Bliley Privacy Rules in Insurance

Updated 11 min read
Key takeaway

The Gramm-Leach-Bliley Act (GLBA) restricts how covered financial institutions handle and share consumers’ nonpublic personal financial information.

  • Insurance underwriters and agents can be financial institutions for these purposes.
  • The rules generally require privacy notices and limit certain disclosures to nonaffiliated third parties, while allowing defined exceptions and requiring limits on reuse or redisclosure.
On this page11 sections
  1. What information is covered?
  2. Consumer versus customer relationships
  3. Privacy notices and their timing
  4. When an opt-out is required—and when exceptions apply
  5. Limits on reuse and redisclosure
  6. Texas implementation for insurance
  7. Examples
  8. A privacy-disclosure checklist
  9. Common exam mistakes
  10. Frequently asked questions
  11. Prepare for the Texas P&C exam

Insurance companies and agents collect information that can reveal far more than a person’s name and policy number. Applications may include income, assets, beneficiaries, addresses, and identification details; servicing creates transaction records, claim files, and payment histories. The Gramm-Leach-Bliley Act (GLBA) privacy provisions address how covered financial institutions give notice about those practices and when they may disclose nonpublic personal financial information to nonaffiliated third parties.

GLBA privacy is not a blanket rule that every piece of insurance information must remain secret from every recipient. It is a framework with defined entities, consumers and customers, information categories, notices, limits, opt-out rights for certain disclosures, and exceptions for servicing, legal compliance, and other purposes. In Texas, insurance entities also look to Chapter 601 of the Insurance Code and the Texas Department of Insurance’s rules at 28 TAC Chapter 22. State rules may be more specific than a short federal summary, so use the rule applicable to the entity and transaction.

TermPlain-language meaningInsurance example
Covered entity / financial institutionAn insurer, agent, or other covered business that provides financial products or services and falls within the applicable ruleAn insurer issuing a policy or an agent arranging coverage
ConsumerAn individual seeking or receiving a covered insurance product or service, depending on the ruleAn applicant, insured, or claimant in a covered relationship
CustomerA consumer with a continuing relationship, as the rules define itA policyholder whose policy has been delivered
Nonpublic personal financial information (NPI)Personally identifiable financial information that is not publicly available, plus certain groupings derived from itApplication income, premium history, transaction details, or report-derived information
Nonaffiliated third partyA party outside the covered entity’s corporate affiliate groupAn outside marketing company or vendor, unless a defined exception applies

What information is covered?

Nonpublic personal financial information generally includes personally identifiable financial information a consumer provides to obtain an insurance product, information resulting from transactions with the insurer or agent, and other information obtained in connection with providing the product or service. The Texas rules give examples such as application information, identifying details, transaction information, balances, payment history, information received from a consumer reporting agency, and lists derived from nonpublic financial details.

Information can remain protected even when it is not itself a bank-account number. The fact that a named person is or was a customer, a policy’s coverage and premium history, or a list assembled from application data may be NPI. Publicly available information and certain health information are addressed separately under the governing provisions, and may not fit the NPI definition in the same way. Health information is subject to other privacy rules and Texas has a separate insurance consumer health-information subchapter; do not assume the GLBA financial-privacy rule is the only applicable regime.

The disclosure context matters. A company may possess a consumer report and also hold application information. GLBA governs privacy and sharing rules for covered financial information, while the Fair Credit Reporting Act separately governs consumer reports, permissible purposes, accuracy disputes, and adverse-action notices. One dataset or event can raise obligations under both laws. The fact that information arrived from a consumer reporting agency does not erase GLBA analysis, and a privacy notice does not replace FCRA notices.

Consumer versus customer relationships

The distinction affects timing and which notices are due. A consumer may apply for insurance and never become a policyholder. A customer generally has a continuing relationship with the financial institution. Under Texas’s insurance privacy rule, an insurer typically establishes a customer relationship when it delivers a policy or contract; an insurance agent may establish one when the consumer obtains insurance through that agent. A one-time consumer may still be entitled to notice before certain nonaffiliated disclosures even without a continuing relationship.

Texas’s rule defines its consumer and covered-entity terms and provides examples that can include an applicant, insured, beneficiary, annuitant, or claimant under specified conditions. The precise coverage of the rule depends on its definitions and context. An insurer should not rely only on the everyday meaning of “customer,” and a person should not assume that no privacy obligations exist simply because an application was denied.

Privacy notices and their timing

A privacy notice describes the institution’s information practices. Federal Regulation P generally requires an initial privacy notice to customers when the customer relationship is established, subject to exceptions. In Texas, 28 TAC §22.8 requires a covered entity to give an initial notice to an individual who becomes its customer no later than establishment of the customer relationship, except as provided by the rule. A consumer who is not a customer generally receives notice before certain nonaffiliated disclosures unless an exception applies.

A notice should be clear and conspicuous and accurately describe relevant practices. Depending on the rule and disclosure choices, it can identify categories of information collected and shared, categories of recipients, how information is protected, and rights to opt out of certain sharing. It is not enough to provide a vague statement that the company “may share information as allowed by law” if the applicable rule calls for more specific categories. Texas rules prescribe content and delivery requirements; the notice cannot be solely an oral explanation.

Annual notices have changed over time, and federal and Texas requirements should not be collapsed into one rule. Federal Regulation P contains an exception for certain institutions that meet its conditions, including limits on disclosures that would trigger opt-out rights and no change in relevant privacy practices. The current Texas insurance rule at 28 TAC §22.9 separately says a covered entity must provide customers an annual notice during the continuing relationship; it expressly excuses notices to former customers. Do not assume a federal exception automatically removes a Texas requirement for a TDI-regulated entity. Confirm the entity’s regulator, the current rule text, and any applicable amendment before relying on an exception.

When an opt-out is required—and when exceptions apply

GLBA’s opt-out right generally concerns disclosures of NPI to nonaffiliated third parties outside enumerated exceptions. If a covered entity plans a disclosure that requires opt-out, it must give the consumer a clear notice of the right and a reasonable opportunity to opt out before the disclosure. It must also explain how to exercise the choice. The opt-out is not a universal right to block every use of information by the insurer or every data transfer between affiliated entities.

The rules include exceptions. Depending on the conditions, an entity may share information to process or service a transaction requested or authorized by the consumer; maintain or service an account; prevent fraud or respond to legal process; comply with regulators or law enforcement; protect against unauthorized transactions; or work with service providers under restrictions. Texas’s rules set out exceptions for processing and servicing transactions and other circumstances. Some exceptions permit sharing without an opt-out; an institution still has to satisfy applicable notice, contract, security, and reuse limits.

For example, an insurer may need to share necessary claim information with an adjuster, repair professional, reinsurer, or vendor to investigate or service a claim. The privacy framework recognizes routine service and administration, but it does not create a free pass to repurpose the data for an unrelated marketing campaign. A business should identify the purpose, recipient, information categories, rule exception, contractual restrictions, and any notice or opt-out step before it discloses NPI.

Limits on reuse and redisclosure

GLBA privacy rules also limit what a recipient can do with information after it receives it. When a financial institution discloses NPI under a permitted exception, the recipient’s use and further disclosure may be restricted to the purpose for which the information was provided. When a consumer opts out, the institution generally must respect the choice for covered disclosures, including certain future sharing, as the rule specifies. Sharing contracts, access controls, and vendor instructions help ensure the information is not reused for an incompatible purpose.

Privacy notices and opt-out processes do not replace data-security duties. GLBA has separate safeguards provisions, and state insurance regulators may impose security requirements on regulated insurers. The federal FTC Safeguards Rule does not necessarily govern an insurance company regulated by a state insurance authority in the same way it governs FTC-jurisdiction financial institutions. Texas insurers should look to their functional regulator and applicable Texas rules. Do not cite the FTC rule as a universal insurance security standard without checking jurisdiction.

Texas implementation for insurance

Texas Insurance Code Chapter 601 directs the Commissioner of Insurance to adopt rules consistent with GLBA for entities regulated by TDI. TDI’s privacy resource identifies the Insurance Consumer Financial Information Privacy Rule at 28 TAC §§22.1–22.26. The rule applies to defined covered entities authorized or regulated by TDI, and some requirements focus on insurance products used primarily for personal, family, or household purposes. Scope depends on the particular section, entity, and disclosure. Review the definitions and exceptions before concluding that a commercial policyholder receives exactly the same consumer notice rights as an individual applicant.

TDI’s FAQ explains that NPI can include application data, transaction information, credit-history details, premium payment history, and certain lists derived from that information. It also describes consumers who may include applicants, policyholders, beneficiaries, and claimants under the stated definitions. The FAQ is a useful plain-language starting point, but TDI expressly says it does not replace the adopted rules. For compliance or a disputed disclosure, consult the current rule text and seek qualified advice.

Examples

An insurer sends information to a claims adjuster

An insurer uses an outside adjuster to inspect a property claim. The disclosure may fit an exception for processing or servicing the transaction, subject to applicable limits and safeguards. The insurer should share information needed for the assignment, not unrelated data simply because the adjuster is a vendor.

A company wants to sell customer lists to a marketer

A list derived from nonpublic financial information may itself be NPI. A sale to an unaffiliated marketer may require notice and an opportunity to opt out, unless a specific exception applies. The entity must not treat an ordinary service-provider exception as a marketing exception.

An applicant is declined and the insurer retains application data

The person may be a consumer even without becoming a customer. If the company plans to disclose NPI to a nonaffiliated third party outside the exceptions, notice may be required before disclosure. If a consumer report caused the decline, FCRA adverse-action requirements are a separate issue.

A privacy-disclosure checklist

  1. Identify the covered entity and the rule that applies to its insurance activity.
  2. Classify the individual as a consumer or customer under the specific rule and relationship.
  3. Identify whether the information is NPI, health information, a consumer report, publicly available information, or another category.
  4. Name the recipient and determine whether it is an affiliate, nonaffiliated third party, or service provider.
  5. State the purpose and identify the exception, if any, that authorizes disclosure without opt-out.
  6. Check whether an initial, revised, annual, or pre-disclosure notice is due and whether an opt-out opportunity is required.
  7. Limit information to what is needed and restrict recipient reuse and redisclosure.
  8. Keep the notice version, consumer choice, disclosure purpose, recipient, and supporting exception in the record.

Common exam mistakes

  • Assuming all insurance information is NPI or that only account numbers qualify.
  • Treating every applicant as a customer even when no continuing relationship was established.
  • Assuming the opt-out right blocks all disclosures, including servicing, legal, or fraud-prevention exceptions.
  • Assuming a privacy notice itself gives permission for any later data use.
  • Confusing GLBA privacy rules with FCRA consumer-report rights.
  • Treating every vendor disclosure as exempt without checking purpose and contract controls.
  • Assuming the annual notice is always required or always unnecessary.
  • Applying a bank regulator’s security rule automatically to a state-regulated insurer without checking jurisdiction.
  • Using an FTC small-business guide instead of current Texas rules for a TDI-regulated insurance entity.

Frequently asked questions

Does GLBA apply to insurance companies? Insurance underwriters and agents can be covered financial institutions, and Texas has insurance-specific implementing rules. What is NPI? It generally includes personally identifiable financial information from applications, transactions, services, and consumer reports, plus certain derived lists. Can consumers opt out of all information sharing? No. The opt-out applies to certain nonaffiliated disclosures, while listed exceptions permit other disclosures. Is an insurance claim file always protected by GLBA? Many financial details can be NPI, but health information, public information, and other categories may be treated under separate rules. Is GLBA the same as FCRA? No. GLBA governs privacy notices and sharing; FCRA governs consumer reports and related rights. Must an insurer send an annual privacy notice every year? Not necessarily; federal and Texas rules allow exceptions if specific conditions are satisfied.

Prepare for the Texas P&C exam

Study the flow: identify the covered entity and information, distinguish consumer from customer, give the required notice, determine whether an opt-out applies, and test for a disclosure exception. Sitonce’s Texas Property and Casualty exam prep covers insurance regulation and consumer privacy.

Common questions

Does GLBA privacy apply to insurers?

Insurance underwriters and agents can be financial institutions under GLBA. Texas implements insurance-specific privacy rules through Chapter 601 and 28 TAC Chapter 22.

What is nonpublic personal financial information?

It generally includes identifiable financial information a consumer provides, information from transactions or services, information from consumer reports, and certain lists derived from it.

Can an insurance customer opt out of all sharing?

No. The opt-out right covers certain disclosures to nonaffiliated third parties. The statutes and rules contain exceptions for purposes such as processing, servicing, legal compliance, and fraud prevention.

Does the privacy notice replace an FCRA adverse-action notice?

No. GLBA privacy notices and FCRA adverse-action notices serve different purposes and can both be required in a transaction.

Are annual privacy notices always required?

Federal Regulation P provides an exception for institutions meeting specified conditions. Texas’s current insurance privacy rule separately requires annual notices to customers during the continuing relationship and excuses former customers, so verify which rule applies.

Do Texas GLBA rules cover every business insurance disclosure identically?

No. Applicability depends on the entity, consumer relationship, information, and specific rule. Read the Texas definitions and exceptions.