Meet us at ITC Vegas 2026 — Booth K-23, September 29 – Thursday, October 1, 2026

Regulatory

Compliance and regulatory guidelines

GLBA Safeguards Rule

15 U.S.C. §6801 · 16 CFR Part 314

What it is
The security half of the Gramm-Leach-Bliley Act. It requires a written information security program, a named individual accountable for it, a written risk assessment, and documented oversight of service providers.
Why it applies
It governs non-public personal information — essentially anything a consumer provides to obtain a financial product, plus the fact of the relationship itself. The definition reaches insurance producers and the vendors who handle their documents, so it follows a dec page wherever that page goes.
For more info: FTC — Gramm-Leach-Bliley Act(opens in a new tab)

CCPA / CPRA

Cal. Civ. Code §1798.100 et seq.

What it is
California's consumer privacy law, as amended by the Privacy Rights Act. It grants rights to access, delete, correct and opt out, requires notice at collection, and expects retention periods to be stated rather than open-ended.
Why it applies
A declarations page carries names, addresses, vehicles and drivers. Once it is processed the consumer holds statutory rights over that data, and a response clock attaches to each one. It also carries a carve-out for records already regulated by GLBA, which is why the two are read together rather than separately.
For more info: California Legislative Information(opens in a new tab)

California Insurance Code §791

Insurance Information and Privacy Protection Act

What it is
The insurance-specific privacy statute. It governs how insurance information is collected, disclosed and used, sets out when authorisation is required, and defines a category called an insurance-support organization.
Why it applies
It is older and narrower than CCPA but applies directly to insurance transactions rather than to consumers generally. Whether a given vendor falls inside its definitions is a threshold question worth settling early, because the answer changes what compliance means.
For more info: California Legislative Information(opens in a new tab)

Cal-FIPA

Cal. Fin. Code §4050–4060

What it is
California's Financial Information Privacy Act, which sets a stricter bar than GLBA on sharing: affirmative consent rather than an opportunity to opt out.
Why it applies
Where GLBA lets a consumer decline, Cal-FIPA often requires them to agree first. For anything that routes a consumer to a third party, that difference decides whether a flow is lawful as designed.
For more info: California Legislative Information(opens in a new tab)

SOC 2

AICPA Trust Services Criteria

What it is
A framework of criteria — security, availability, processing integrity, confidentiality and privacy — against which an independent CPA firm examines a service organization and issues a report. A Type I report covers whether controls were suitably designed at a point in time; a Type II covers whether they operated effectively across a period, usually three months or longer.
Why it matters
The statutes above set the obligations; SOC 2 is the common language for showing a counterparty how they are met. When an agency or a platform shares regulated data with a vendor, this is the report their diligence asks for, because it is written by an examiner with no stake in the answer.
For more info: AICPA(opens in a new tab)