Regulatory
Compliance and regulatory guidelines
GLBA Safeguards Rule
15 U.S.C. §6801 · 16 CFR Part 314
- What it is
- The security half of the Gramm-Leach-Bliley Act. It requires a written information security program, a named individual accountable for it, a written risk assessment, and documented oversight of service providers.
- Why it applies
- It governs non-public personal information — essentially anything a consumer provides to obtain a financial product, plus the fact of the relationship itself. The definition reaches insurance producers and the vendors who handle their documents, so it follows a dec page wherever that page goes.
CCPA / CPRA
Cal. Civ. Code §1798.100 et seq.
- What it is
- California's consumer privacy law, as amended by the Privacy Rights Act. It grants rights to access, delete, correct and opt out, requires notice at collection, and expects retention periods to be stated rather than open-ended.
- Why it applies
- A declarations page carries names, addresses, vehicles and drivers. Once it is processed the consumer holds statutory rights over that data, and a response clock attaches to each one. It also carries a carve-out for records already regulated by GLBA, which is why the two are read together rather than separately.
California Insurance Code §791
Insurance Information and Privacy Protection Act
- What it is
- The insurance-specific privacy statute. It governs how insurance information is collected, disclosed and used, sets out when authorisation is required, and defines a category called an insurance-support organization.
- Why it applies
- It is older and narrower than CCPA but applies directly to insurance transactions rather than to consumers generally. Whether a given vendor falls inside its definitions is a threshold question worth settling early, because the answer changes what compliance means.
Cal-FIPA
Cal. Fin. Code §4050–4060
- What it is
- California's Financial Information Privacy Act, which sets a stricter bar than GLBA on sharing: affirmative consent rather than an opportunity to opt out.
- Why it applies
- Where GLBA lets a consumer decline, Cal-FIPA often requires them to agree first. For anything that routes a consumer to a third party, that difference decides whether a flow is lawful as designed.
SOC 2
AICPA Trust Services Criteria
- What it is
- A framework of criteria — security, availability, processing integrity, confidentiality and privacy — against which an independent CPA firm examines a service organization and issues a report. A Type I report covers whether controls were suitably designed at a point in time; a Type II covers whether they operated effectively across a period, usually three months or longer.
- Why it matters
- The statutes above set the obligations; SOC 2 is the common language for showing a counterparty how they are met. When an agency or a platform shares regulated data with a vendor, this is the report their diligence asks for, because it is written by an examiner with no stake in the answer.
