GLBA, Financial privacy and customer data
16 CFR Part 314
- Was diese Seite ist
- GLBA, Financial privacy and customer data
- Gegen die amtliche Quelle geprüft
- 2026-08-15Aktuell
- Verantwortlicher Herausgeber
- ExploreWorld Legal, RedaktionHaftungsposition
Kurze Antwort
Does GLBA apply to your operation, and which paragraph decides?
GLBA rests on 16 CFR Part 314 and is tested here by a deterministic rule tree of 5 rules with a coverage score of 100 percent. The tree reads your facts, names the paragraph that decides the question and returns an outcome carrying citation, content hash and read date 2026-08-15. The outcome is a machine classification, not a compliance decision.
16 CFR Part 314Gegen den Herausgeber geprüft 2026-08-15Amtlicher Text
Ein Quellenverweis, keine Rechtsberatung.
- Rechtsordnung
- Bundesebene
- Risikodimensionen
- Datenschutz, Sicherheit, Finanzberichterstattung
- Klasse
- Klasse 1
- Abdeckung
- 100 %
- Wirkung
- 5/5
- Gelesen
- 2026-08-15
Quellkette
Jeder Block der Registerzeile hat eine eigene Adresse, sodass ein Ergebnis bis auf den Absatz zitiert werden kann. Der Knoten trägt den Verweis, den Umfang, den Link zum offiziellen Text und die Ergebnisse im Baum, die auf dem Block ruhen.
- Information security program
16 CFR 314.4(a)
A written programme with a named qualified individual responsible for it.
- Risk assessment
16 CFR 314.4(b)
Written assessment of foreseeable risks to customer information.
- Safeguards
16 CFR 314.4(c)
Access controls, encryption, multi-factor authentication, disposal and change management.
- Notification of a security event
16 CFR 314.5
Notice to the agency when unencrypted customer information of 500 or more consumers is acquired without authorisation.
Der Regelbaum
Die Regeln werden von oben nach unten geprüft. Die Bedingungen stammen aus dem Regeltext, und das Ergebnis verweist auf die Blöcke der Registerzeile, auf denen es ruht.
glba-program
The written information security program is absent
unzulässig · Die Anforderung gilt · program
16 CFR 314.3(a) requires a written information security program appropriate to the size and complexity of the activity and the information handled.
glba-qualified
No qualified individual is designated
Risiko · Die Anforderung gilt · program, controls
16 CFR 314.4(a) requires designating a qualified individual responsible for the program, and 16 CFR 314.4(i) requires reporting to the board or equivalent.
glba-encryption
Encryption is required, or a documented equivalent control
Risiko · Die Anforderung gilt bedingt · controls
16 CFR 314.4(c)(3) requires encryption of customer information at rest and in transit, or an equivalent compensating control approved in writing by the qualified individual.
glba-small
The full rule applies, including risk assessment and incident response
Risiko · Die Anforderung gilt · risk-assessment, notification, controls
16 CFR 314.6 exempts those maintaining information on fewer than 5,000 customers from certain parts. At 5,000 customers or more the written risk assessment in 16 CFR 314.4(b), the incident response plan in 314.4(h) and the board report in 314.4(i) also apply.
glba-base
The rule applies, with the exemption for smaller holdings
Risiko · Die Anforderung gilt bedingt · program, risk-assessment
16 CFR 314.1 states the scope for financial institutions under the Commission's jurisdiction. 16 CFR 314.6 exempts those maintaining information on fewer than 5,000 customers from parts of 314.4.
Ergebnis
zulässig · Außerhalb des Anwendungsbereichs
The rule yields no requirement for the facts supplied
No activity is stated to be financial under 16 CFR 314.1 and 16 CFR 314.2.
fallback · sha256:sha256:8a31c1c15cc39333fa03a89ba
Überwachung
Das Journal zeigt, was sich in der Registerzeile bewegt hat, mit Hash davor und danach. Die Wirkungszahl folgt einer Regel, die im Klartext steht.
So wird die Wirkung berechnet: Grund: tillagd eller borttagen uppgift ger 3, ändrad uppgift 2, omläsning utan ändring 0. Tillägg: +1 när ändringen rör status eller tillämpningsdatum. Tillägg: +1 när agenten ligger i klass 1. Siffran begränsas till 0 till 5.
2026-08-15 · 0/5 · lasning
Raden läst mot den officiella publiceringen utan ändring
2023-06-09 · 4/5 · tillampningsdatum, status
Regeln började tillämpas enligt utgivaren
2021-12-09 · 5/5 · antagande, identifierare, status
Regeln antogs enligt 16 CFR Part 314
Aufsicht
Entsprechungen in der EU
- nis2-2022-2555 · Båda texterna kräver ett skriftligt säkerhetsprogram, en dokumenterad riskbedömning och anmälan av allvarliga incidenter. EU-texten gäller väsentliga verksamheter, den amerikanska regeln finansiella institut.
Artefakte und Integrität
- https://legal.exploreworldai.com/api/public/v1/us-agents/glba/manifest.json
- https://legal.exploreworldai.com/api/public/v1/us-agents/glba/run
- https://legal.exploreworldai.com/api/public/v1/us-agents/glba/monitor.json
- sha256:3810851e37977f8637dece51a038643fbb7f777178da3128492e0a6203729d0d
- sha256:3d1a8b0a25f771aa833b3764d22468d59e410439b1113c204bb3c5c1eea20eaf
Das Verdikt ist eine maschinelle Einordnung des Ergebnisses, keine Rechtsberatung und keine Compliance-Entscheidung. Verantwortungsposition · 16 CFR Part 314
Überprüfbare Vertrauenssignale
- Sechs feste Blöcke, eine Quelle je Zeile
- Kein Satz von einem Sprachmodell geschrieben
- Version und Lesedatum an jeder Antwort
- Keine Kundendaten, keine Dokumente, keine Beratung
- Modellkarte und Prüfung nach der KI-Verordnung veröffentlicht