A bank can disclose customer information to third parties in a wide range of situations, and much of that sharing happens without your permission or even your knowledge. The Gramm-Leach-Bliley Act (GLBA) is the main federal law on the subject. It lets you block some sharing, particularly with outside companies for marketing, but it also permits or requires banks to share your information with service providers, affiliates, credit bureaus, and government agencies. Knowing which category a given disclosure falls into is the difference between a right you can exercise and a rule you simply have to live with.
What Information the Law Protects
The GLBA protects “nonpublic personal information,” or NPI. That means any personally identifiable financial information a bank collects in connection with providing you a financial product or service, as long as it is not publicly available.1FDIC. VIII-1 Gramm-Leach-Bliley Act (Privacy of Consumer Financial Information) Your Social Security number, account balances, transaction history, loan payments, and credit report data all fall inside this definition.2Federal Trade Commission. How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act
One boundary matters before you go further. The GLBA protects individuals who use financial products for personal, family, or household purposes. It does not cover business accounts, including a sole proprietor’s business banking.2Federal Trade Commission. How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act If you run a small business, your bank has significantly more freedom to share information about those accounts than about your personal ones.
Sharing You Can Block
Every bank is required to send you a privacy notice explaining what it collects, whom it shares with, and how it protects the data. A bank that only shares information as permitted by law and has not changed its practices does not have to send this notice every year.3eCFR. 12 CFR 1016.5 – Annual Privacy Notice Requirement for Institutions That Do Not Disclose
The notice is also where you’ll find your opt-out rights. If your bank plans to share NPI with unaffiliated companies for purposes such as marketing, you can direct it not to. The bank has to give you a reasonable window before any sharing occurs, typically at least 30 days, and it has to make the opt-out easy to use, such as a reply form, toll-free number, or online portal.2Federal Trade Commission. How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act
Two practical points on opt-outs. Once you opt out, it stays in effect even after you close the account, until you cancel it in writing or electronically. But opening a new account with the same bank starts a new relationship, and you have to opt out again.2Federal Trade Commission. How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act
Whether or not you opt out, banks are flatly prohibited from sharing your account numbers, credit card numbers, or access codes with nonaffiliated third parties for use in telemarketing, direct mail, or email marketing.4eCFR. 12 CFR 1016.12 – Limits on Sharing Account Number Information for Marketing Purposes That prohibition is absolute; no notice or opt-out changes it.
Marketing by the Bank’s Affiliates
Sharing inside a bank’s corporate family, such as between the bank and its brokerage or insurance affiliate, works under the Fair Credit Reporting Act rather than the GLBA opt-out. Affiliates can generally share your information for ordinary business purposes. When an affiliate wants to use information bearing on your creditworthiness or financial capacity to send you marketing, though, it must clearly disclose the practice, offer you a simple way to opt out, and honor it if you exercise it.5eCFR. 16 CFR 680.21 – Affiliate Marketing Opt-Out and Exceptions
The affiliate marketing opt-out does not apply if the company already has a pre-existing business relationship with you, if you initiated the communication, or if you specifically authorized the solicitations.5eCFR. 16 CFR 680.21 – Affiliate Marketing Opt-Out and Exceptions So if your bank’s investment affiliate already handles your IRA, it can pitch other products to you without triggering the opt-out right.
Sharing You Cannot Block
Several kinds of disclosure are baked into how banking works. No opt-out applies, and no consent is asked.
Service Providers
Banks contract with outside companies to print checks, process transactions, and mail statements. NPI can flow to these vendors as long as the bank has disclosed the practice in its privacy notice and has a contract requiring the vendor to keep the information confidential and use it only for the contracted purpose.1FDIC. VIII-1 Gramm-Leach-Bliley Act (Privacy of Consumer Financial Information)
Joint Marketing With Other Financial Companies
A bank can share NPI with another financial institution to jointly offer a product, such as a co-branded credit card. You get no opt-out, but the arrangement must be governed by a written contract limiting the partner’s use of the data to the joint marketing purpose.6eCFR. 16 CFR 313.13 – Exception to Opt Out Requirements for Service Providers and Joint Marketing
Credit Bureaus
Banks routinely report your loan balances, credit card activity, payment history, and credit limits to Equifax, Experian, and TransUnion.7OCC (Office of the Comptroller of the Currency). Credit Reporting The Fair Credit Reporting Act requires that the reported information be accurate, and it gives you the right to dispute errors on your credit report.8Consumer Financial Protection Bureau. List of Consumer Reporting Companies
Disclosures to the Government
Federal law forces banks to send certain information to government agencies. Your consent isn’t part of the equation.
Court Orders and Subpoenas
When a bank receives a valid court order, subpoena, or search warrant, it complies. In most cases involving administrative or judicial subpoenas or formal written requests, the Right to Financial Privacy Act (RFPA) requires the government to notify you before it accesses your records, so you have a chance to challenge the request.
Once notified, you have 10 days from service (or 14 days from mailing) to file a motion to quash. The filing needs a sworn statement explaining why the records aren’t relevant to a legitimate law enforcement inquiry or why the government hasn’t followed proper procedure. The court then orders the government to respond, and the entire matter has to be decided within seven calendar days of that response.9Office of the Law Revision Counsel. 12 USC Chapter 35 – Right to Financial Privacy
The government can ask a court to delay notifying you for up to 90 days if early notice could endanger someone, cause flight from prosecution, lead to destruction of evidence, or seriously jeopardize an investigation.10Federal Reserve. Right to Financial Privacy Act – Compliance Handbook Search warrants can proceed under the same delayed-notice standard. In those situations your records may already have been reviewed by the time you find out, and the RFPA challenge process remains the sole judicial remedy available.9Office of the Law Revision Counsel. 12 USC Chapter 35 – Right to Financial Privacy
Large Cash Transactions
The Bank Secrecy Act requires banks to file a Currency Transaction Report with the Financial Crimes Enforcement Network (FinCEN) for any cash transaction over $10,000, including deposits, withdrawals, and currency exchanges.11FFIEC BSA/AML Manual. Assessing Compliance with BSA Regulatory Requirements – Currency Transaction Reporting The bank doesn’t need your permission and doesn’t have to tell you it filed. Splitting a transaction into smaller pieces to stay under the threshold is itself a federal crime.
Suspicious Activity
If a bank suspects a transaction involves money laundering, fraud, or other illegal activity, it files a Suspicious Activity Report (SAR) with FinCEN. Federal law specifically prohibits the bank from telling you a SAR has been filed. No employee, officer, or contractor of the bank may reveal it, and no government employee who learns of it may either.12Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority If your account is frozen or closed and the bank won’t explain why, a SAR is often the reason. The bank is legally barred from saying so.
Tax Reporting
Banks report interest income of $10 or more to the IRS on Form 1099-INT.13Internal Revenue Service. About Form 1099-INT, Interest Income You get a copy for your own return, but the data goes to the IRS regardless of your preferences.14Internal Revenue Service. Topic No. 403, Interest Received
When a Breach Exposes Your Information
Federal banking regulators require banks to have a response program for unauthorized access to customer data. When a bank finds out someone has gained access to sensitive information, such as your name combined with your Social Security number, account number, or login credentials, it must investigate promptly and determine whether misuse has occurred or is reasonably possible. If misuse is likely, the bank must notify you as soon as possible. Law enforcement can ask the bank to delay your notice if giving it would interfere with a criminal investigation.15Board of Governors of the Federal Reserve System. Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice
Many states have their own breach notification laws, some with tighter deadlines than the federal standard. The GLBA sets a floor, and states can layer additional privacy protections on top of it. What applies to you depends partly on where you live.
If You Think Sharing Was Improper
Start with the bank. Contact customer service or ask for the privacy officer, describe what you think happened, and ask for an explanation. A lot of these situations turn out to involve sharing the privacy notice disclosed, which a quick conversation can clear up.
If the bank’s answer doesn’t resolve it, file a complaint with the Consumer Financial Protection Bureau through its complaint portal.16Consumer Financial Protection Bureau. Submit a Complaint The CFPB forwards the complaint to the bank, which generally responds within 15 days, or up to 60 days for more complex matters. You then have 60 days to review the response and give feedback.17Consumer Financial Protection Bureau. Learn How the Complaint Process Works
If that doesn’t produce a satisfactory result, an attorney who handles consumer financial privacy can evaluate whether the bank violated the GLBA, the FCRA, or state law. Because states may provide remedies federal law alone doesn’t, someone familiar with your state’s rules is worth finding.