Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

Gramm-Leach-Bliley Privacy Notices for Insurance Customers

Updated 11 min read
Key takeaway

GLBA privacy rules apply to insurers and other financial institutions for covered products and services.

  • Required notices explain information practices, and some nonaffiliate disclosures require an opt-out opportunity.
  • Texas law adds requirements, so agents should use carrier-approved notices and avoid promising that all sharing is barred.
On this page7 sections
  1. Who is covered by GLBA?
  2. What the privacy notice explains
  3. When does a customer get an opt-out?
  4. Medical information and other separate rules
  5. An agent’s practical workflow
  6. Exam traps and examples
  7. How to answer privacy questions accurately

A life insurance applicant may ask why an insurer wants a privacy notice before issuing a policy. The short answer is that insurance companies handle nonpublic personal information under federal and state privacy rules. GLBA requires covered financial institutions to give notices describing their information practices and, for some disclosures to nonaffiliated third parties, to provide an opportunity to opt out. Texas also regulates insurance privacy through Insurance Code Chapter 601 and Texas Department of Insurance rules. A notice is an explanation of practices and rights; it is not a promise that information will never be shared.

Federal framework
GLBA and its implementing privacy and safeguards rules apply to covered financial institutions, including insurers.
Information
Nonpublic personal information includes identifiable financial information obtained in connection with a financial product or service.
Opt out
Generally relates to certain disclosures to nonaffiliated third parties, subject to statutory and regulatory exceptions.
Texas overlay
Texas Insurance Code Chapter 601 and TDI rules in 28 TAC Chapter 22 regulate insurance information practices.
Agent practice
Use the insurer’s current privacy notice, explain it accurately, and route requests to the insurer’s privacy contact.
Key distinction
A notice does not mean every disclosure requires consent, and an exception does not mean every disclosure is allowed.

Who is covered by GLBA?

GLBA applies to financial institutions that are significantly engaged in providing financial products or services. The FTC identifies insurance companies among the businesses that may be financial institutions. A life insurer, annuity issuer, or certain insurance intermediary can therefore be subject to privacy obligations, depending on the activity and the regulator with jurisdiction. The label ‘financial institution’ is a legal category, not a statement that a company is a bank.

A producer may receive information on behalf of an insurer, submit an application, or help service a policy. That does not automatically make every individual agent responsible for every notice or disclosure decision. The insurer’s compliance procedures identify who gives the notice, which version applies, when it must be provided, and how an opt-out is recorded. Some agencies are themselves covered institutions or service providers, depending on their role. Follow the written procedure rather than assuming the carrier handles every task or that the producer has no privacy responsibilities.

The federal privacy rule focuses on nonpublic personal information (NPI), broadly meaning personally identifiable financial information that a consumer provides to obtain a financial product or service, that results from a transaction, or that is otherwise obtained in connection with providing such a product or service. Publicly available information and certain aggregated or otherwise excluded data may be treated differently under the applicable definition. The analysis is about the type and context of information, not whether the customer considers it sensitive.

Information exampleTypical privacy questionPractical handling
Application answers about finances, identity, or coverageWas this obtained in connection with an insurance application or service?Collect only through approved systems and disclose through authorized channels.
Policy values, premium and beneficiary dataDoes the record identify a customer and concern a financial product?Treat as confidential and limit access to people with a business need.
Medical history or test resultsAre separate health-information rules also implicated?Use the insurer’s specific authorization and secure medical-information process.
Public address listingIs it actually publicly available, and is another restriction relevant?Do not infer that public availability permits unrestricted use.
Aggregate statistics without customer identifiersCan the information reasonably identify an individual?Use approved de-identification and data-sharing standards.

What the privacy notice explains

A privacy notice describes categories of information collected and disclosed, categories of affiliates and nonaffiliated third parties receiving information, and the institution’s confidentiality and security practices. When a consumer-facing institution reserves the right to disclose NPI to nonaffiliated third parties outside an exception, the notice generally explains the right to opt out and how to exercise it. The notice is not just a consent form. It informs a person about the institution’s practices and applicable choices.

The initial notice is generally delivered when a customer relationship is established or, for a consumer who is not a customer, before information is disclosed in a way that triggers notice requirements. The exact timing and method depend on the institution’s role, the transaction, and applicable exceptions. A life applicant is a consumer even if the insurer ultimately declines the application. Texas TDI guidance specifically addresses notices to consumers and customers; an agent should not tell a declined applicant that privacy rules never applied because no policy issued.

Annual notice rules require careful jurisdictional reading. Federal amendments created an exception from annual delivery for institutions that meet conditions, including that they do not share information in a manner triggering opt-out rights and have not changed their practices. Texas insurance regulations and TDI guidance may impose separate notice obligations. Do not assume that a federal exception automatically eliminates every Texas obligation. A carrier’s compliance department should determine the applicable schedule and provide the approved notices.

A notice may be delivered electronically where legal conditions are satisfied and the customer has agreed or otherwise meets electronic-delivery requirements. A producer should not substitute an old PDF, a generic agency policy, or an informal explanation for the approved notice. If a customer says a notice was not received, record the concern and refer it to the carrier. The insurer can check the delivery system, provide a fresh notice, and correct the customer record if necessary.

When does a customer get an opt-out?

The GLBA opt-out right generally applies when a financial institution discloses a consumer’s NPI to a nonaffiliated third party outside the permitted exceptions. A nonaffiliate is generally an entity that is not under common ownership or control. Customers should receive a reasonable opportunity to opt out before the relevant disclosure. The notice must explain how to exercise the choice, such as a specified telephone number, website, or form.

The opt-out is not a universal veto on information sharing. GLBA regulations allow disclosures for specified purposes, including processing or servicing a transaction requested or authorized by the consumer, maintaining or servicing an account, fraud prevention, legal compliance, and certain joint marketing arrangements subject to conditions. The precise exception must fit the facts and governing rule. A producer should never characterize an exception as permission to share information for any business purpose.

Sharing with an affiliate is analyzed differently from sharing with a nonaffiliate under the GLBA privacy rule. Other laws can still restrict affiliate sharing, particularly when the information is medical or is a consumer report. Texas law may also impose requirements. The practical answer to a customer should be based on the insurer’s notice and a compliance-approved explanation, not a broad statement that affiliates can always exchange records freely.

Texas has its own insurance privacy framework. Insurance Code Chapter 601 and TDI’s 28 TAC Chapter 22 address notice, opt-out, and disclosure rules for insurance institutions and agents within their scope. TDI explains that a consumer includes a person who applies for insurance, whether or not a policy is issued. Its guidance also explains notice timing when nonaffiliated disclosures are contemplated. For independent agents who seek quotes from multiple insurers, specific rules address notices; that is not a blanket exemption for all agency activity.

Medical information and other separate rules

Life underwriting often involves health information. GLBA privacy rules do not replace every health privacy law, and HIPAA does not automatically cover every life insurance insurer or agent. Texas Insurance Code Chapter 602 addresses insurance-related health information, while the federal FCRA restricts the use and disclosure of medical information in consumer reports. A life insurer may also require written authorizations for medical records or testing. Treat health information as a separate compliance track and use the carrier’s authorization language.

A customer’s authorization to obtain medical records is not necessarily the same thing as a GLBA opt-out, and an opt-out from certain nonaffiliate sharing does not erase an authorization or other legal basis for underwriting disclosures. Each document has a specific purpose. Explain the form using its own language and do not tell a customer that signing one form waives every privacy right.

Consumer reports also have separate FCRA rules. If an insurer uses a report from a consumer reporting agency to take adverse action, it may have to give a notice identifying the agency and explaining the consumer’s rights. The agent should not call a MIB record or an insurer’s internal underwriting note a credit report unless it meets the relevant definition. See our guides to MIB reports and medical information and FCRA and insurance applications for the related report rules.

An agent’s practical workflow

At the first customer contact, use the current carrier or agency privacy notice and document delivery as the procedure requires. If the customer has questions about categories of information or recipients, point to the specific notice section. Do not promise that information is never shared, that the customer can block disclosures necessary to process an application, or that the insurer can ignore an opt-out request. The notice and rule determine those issues.

When a customer exercises an opt-out, use the approved channel promptly. An agent should not keep a note in a local spreadsheet and assume that the preference will reach every insurer or vendor. Confirm whether the opt-out applies to one institution, particular categories of disclosure, or a legally specified process. Escalate questions about scope or an alleged unauthorized disclosure to the privacy office. Keep the customer’s request secure and do not circulate it more widely than needed.

Before sending an application, medical authorization, or policy detail to someone outside the insurer, ask why the recipient needs it and which approved process permits the transfer. Verify identity and recipient information. Do not email unencrypted files to a personal address, include sensitive details in a subject line, or use a customer’s consent as a reason to bypass carrier security. If an adviser, employer, family member, or premium payer requests information, confirm that the customer has authorized the disclosure and that applicable rules allow it.

If you discover a misdirected email or unauthorized disclosure, promptly follow the carrier’s incident-reporting procedure. Do not quietly delete evidence, contact every affected person without direction, or make a legal conclusion about whether breach notice is required. The institution will assess the event, preserve logs, involve its privacy and security teams, and take required steps. The agent’s immediate value is fast, accurate reporting.

Exam traps and examples

Trap one: confusing a privacy notice with a release of information. A notice explains practices; a specific authorization may separately permit access to certain records. Trap two: believing an opt-out prevents every disclosure. Several permitted operational and legal exceptions exist. Trap three: assuming an applicant is not a consumer because the application was declined. Texas TDI guidance says applicants remain consumers for notice purposes. Trap four: applying a federal annual-notice exception to a Texas insurance relationship without checking state rules and carrier policy.

Example: Maria applies for a life policy and receives the insurer’s privacy notice. The insurer obtains an underwriting report from an outside reporting company under an authorization. If the carrier later shares information with a service provider to process the application, a rule exception may apply; the agent should not describe that as an opt-out violation without analyzing the purpose and rule. If the insurer wants to share NPI with a nonaffiliate for a purpose outside an exception, opt-out rules may apply before disclosure.

Example: An independent agent sends one application to several carriers to request offers. TDI’s rules and guidance address notice in this shopping context, but each insurer still has its own compliance obligations. The agent should use the approved notice and workflow. The fact that one agent submits applications to multiple companies does not create a general right to circulate the applicant’s data to any unrelated business.

Example: A customer asks the agent to provide the policy file to an adult child. A family relationship is not itself proof of authority. Verify the customer’s direction and scope, check for a valid power of attorney or other authority where needed, and use the carrier’s secure disclosure process. A beneficiary designation does not ordinarily entitle a living beneficiary to all underwriting records.

How to answer privacy questions accurately

The safest clear explanation is: ‘This notice tells you what information the insurer collects and how it may use or share it. Some sharing is needed to underwrite, issue, service, or protect the policy, and some disclosures are permitted or required by law. The notice explains when you may opt out. I can help direct your question to the privacy office.’ This avoids overpromising while giving the customer a practical next step.

For exam study, separate four concepts: the covered institution, the type of protected information, the kind of recipient, and the purpose of disclosure. Then ask whether the applicable federal or Texas rule calls for a notice, opt-out, authorization, or exception. In a real file, follow current company instructions. GLBA establishes a framework, while state rules and other statutes can add protections or duties.

Common questions

Does every life insurance applicant receive a GLBA privacy notice?

Covered institutions have notice duties under federal and Texas rules, and Texas TDI guidance treats an applicant as a consumer even if the insurer declines the application. The exact timing and delivery responsibility depend on the transaction and applicable exceptions. Use the insurer’s approved workflow.

Can a customer opt out of every disclosure of insurance information?

No. The GLBA opt-out generally concerns certain disclosures of nonpublic personal information to nonaffiliated third parties. Disclosures for servicing, processing, fraud prevention, legal compliance, and other specified purposes may be excepted. Other laws can impose separate limits.

Does GLBA mean an insurer can share medical records freely?

No. Medical information may be subject to separate federal and Texas requirements, including FCRA restrictions on medical information in consumer reports and Texas Insurance Code Chapter 602. Follow applicable authorizations and carrier procedures.

Can an agent use an old privacy notice if the customer already has a policy?

Use only the current notice approved for the insurer and the transaction. Notice versions and delivery rules can change, and the insurer’s compliance team determines what to provide and when.

Does the federal annual-notice exception eliminate Texas notice requirements?

Do not assume so. Texas insurance privacy rules may impose separate duties. The insurer should determine current federal and Texas requirements for the relationship and its information-sharing practices.