Skip to main content
Aggregate PYMNTS 金融科技 19 Aug 2026 - 00:01

Congress Considers Overhaul of Federal Financial Privacy Law, But There’s a Catch

RSS 官方收录 · 可信分层展示

关键摘要

Congress is considering a major rewrite of federal financial privacy law that could offer banks and other financial companies a consequential bargain: substantially stronger consumer rights over financial data in exchange for a single national privacy regime.…

  • The Guidelines for Use, Access, and Responsible Disclosure of Financia…
  • 8398, would modernize the privacy provisions of the Gramm-Leach-Bliley…
  • Introduced in April by House Financial Services Committee Vice Chairma…

摘要引擎:抽取

正文提要

Congress is considering a major rewrite of federal financial privacy law that could offer banks and other financial companies a consequential bargain: substantially stronger consumer rights over financial data in exchange for a single national privacy regime.

The Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act, or GUARD Financial Data Act, H.R. 8398, would modernize the privacy provisions of the Gramm-Leach-Bliley Act, the 1999 law that remains the foundation of federal financial-data privacy regulation.

Introduced in April by House Financial Services Committee Vice Chairman Bill Huizenga (R-Mich.), with committee Chairman French Hill (R-Ark.) and Reps. Andy Barr (R-Ky.) and Bryan Steil (R-Wis.), the proposal responds to the explosion in the volume and uses of financial data since GLBA was enacted.

The legislation would shift GLBA beyond its traditional focus on disclosures and privacy notices toward regulation of how financial institutions collect, use and retain consumer information.

Financial institutions generally would have to limit collection to information that is adequate, relevant and reasonably necessary for providing a product or service. Consumers would receive expanded information about data practices and rights to obtain copies of their information, while former customers could request deletion subject to exceptions. The bill also would require affirmative consent for certain uses of sensitive information.

In return, financial companies could gain something the industry has sought for years: broad federal preemption of state financial-privacy requirements.

According to the congressional intelligence service Legis1, the bill would establish GLBA Title V as the uniform national standard and includes both entity- and data-level preemption. Supporters argue that would reduce compliance costs and eliminate the growing patchwork created as states adopt increasingly expansive privacy statutes.

That trade-off has already attracted industry support. The American Bankers Association said the GUARD Act and companion SECURE Data Act contain several longstanding industry priorities and praised lawmakers for attempting to create consistent federal oversight while preserving the GLBA regulatory framework for banks.

Preemption, however, could become a major obstacle, according to a Congressional Research Service report cited by Legis1. The National Conference of State Legislatures has opposed the legislation’s broad preemption provisions, arguing they could prevent states from responding to emerging privacy risks.

For financial institutions, another complication is the proposal’s intersection with open banking.

The GUARD Act creates a statutory definition of “financial data aggregator,” covering businesses primarily engaged in accessing, aggregating, collecting, processing or disclosing nonpublic personal information.

That puts the legislation on a potential collision course with the Consumer Financial Protection Bureau’s Section 1033 framework, which is designed to enable consumers to authorize third parties to obtain financial account information. Financial institutions could therefore face two policy objectives simultaneously: making financial data portable at consumers’ direction while limiting unnecessary collection, use and retention of the same information.

That tension could become more significant as the CFPB revisits its open-banking regulations.

The implications also extend to artificial intelligence. Banks and FinTechs increasingly use large datasets for fraud detection, underwriting, personalization, risk management and AI systems. A statutory requirement that data collection be necessary for providing products or services could force firms to examine whether secondary uses of customer information, including model development and AI analytics, remain permissible.

Financial institutions should therefore watch the legislation’s final definitions of permissible data collection and sensitive information, its treatment of aggregators and third parties, and any reconciliation with Section 1033 requirements.

They should also scrutinize preemption. Stronger federal privacy obligations could represent a significant new compliance burden if they merely sit atop state requirements. They could look considerably different economically if they replace those requirements nationwide.

The GUARD Act ultimately reflects how much financial services have changed since GLBA. The original framework largely contemplated financial institutions holding customer information. Open banking increasingly requires them to move it, while AI gives institutions powerful new ways to analyze and use it.

Congress is now trying to govern all three activities under one framework — while determining whether stronger consumer control over financial data is a price the industry is willing to pay for one national set of rules.

The post Congress Considers Overhaul of Federal Financial Privacy Law, But There’s a Catch appeared first on PYMNTS.com.

打开官方原文 站点原文页 可信分区 本信源更多 今日简报 分享图 RSS 稍后再看列表