Skip to content
RiskTemplates · The Daily Brief Saturday, September 19, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Data Privacy

Montana and Connecticut Just Narrowed the GLBA Exemption. Every Nonbank Financial Institution Has New Privacy Obligations.

Montana's privacy law amendments took effect October 1, 2025. Connecticut's took effect July 1, 2026. Both states moved from a broad entity-level GLBA exemption to a narrower data-level exemption — meaning fintechs, nonbank mortgage companies, and other non-depository financial institutions that relied on GLBA for blanket coverage are now subject to state privacy law for data outside GLBA's scope.

Table of Contents

If you work at a fintech, nonbank mortgage company, auto finance operation, or any other non-depository financial institution, there is a good chance someone on your team believes that being subject to GLBA means you don’t have to worry about state privacy laws. That belief has been eroding for several years. In Montana, it stopped being true on October 1, 2025. In Connecticut, it stopped being true on July 1, 2026.

This is not a hypothetical compliance alert. It is a closed legal question with a compliance deadline that has already passed in one state and just passed in another.

TL;DR

  • Montana (eff. Oct 1, 2025) and Connecticut (eff. July 1, 2026) both moved from entity-level to data-level GLBA exemptions — nonbank financial institutions that relied on GLBA for blanket coverage are now subject to state privacy law for data outside GLBA’s scope
  • Fintechs, nonbank mortgage companies, online lenders, and auto dealers with finance operations are the most exposed — they do not qualify for Connecticut’s narrow residual entity-level exemption for pure banks/credit unions
  • Four compliance obligations are triggered: privacy notice update, consumer rights infrastructure, data inventory, and processor contracts
  • California’s CPPA ADMT regulations (eff. Jan 1, 2027 for automated decisioning) add a separate layer for organizations using automated systems to make credit, fraud, or eligibility decisions about California consumers

What the GLBA Exemption Actually Was — and Wasn’t

Before diving into what changed, it helps to understand what the GLBA exemption in state privacy laws was designed to do.

GLBA — the Gramm-Leach-Bliley Act — requires financial institutions to protect the privacy of nonpublic personal information collected from consumers in connection with providing a financial product or service. It also requires disclosure of privacy practices through annual notices and gives consumers a limited right to opt out of information sharing with non-affiliated third parties. The FTC’s Safeguards Rule, enforceable since 2023, extends the data security piece. We’ve covered the Safeguards Rule’s nine requirements in detail — the relevant point here is that GLBA already imposes a compliance framework on financial institutions.

When states began passing comprehensive consumer privacy laws, most of them included an exemption for “financial institutions” subject to GLBA — or for “data” subject to GLBA — to avoid duplicative regulation. The intent was to say: if GLBA already covers you, we won’t pile on.

The ambiguity was always in how broad that exemption was. Two models emerged:

Exemption TypeWho QualifiesWhat’s Covered
Entity-levelEntire organization if it’s a GLBA “financial institution”All personal data held by that entity
Data-levelAny organizationOnly data actually subject to GLBA’s protections

California was always a data-level exemption state under CCPA/CPRA. Montana and Connecticut were entity-level — until they weren’t.

Montana Goes First

Montana’s Consumer Data Privacy Act (MTCDPA) took effect in October 2024. The original statute included a broad entity-level exemption for financial institutions subject to GLBA. In 2025, Montana amended its law to narrow that exemption to the data level, effective October 1, 2025.

For nonbank financial institutions in Montana — fintechs offering services to Montana residents, nonbank mortgage companies, online lenders — the practical effect was immediate: any personal information they collect that isn’t directly covered by GLBA became subject to Montana privacy law. Website analytics. Email marketing lists. Loyalty or rewards program data. App behavioral data. Employment records. Survey responses.

For organizations that had done zero state privacy law compliance work on the assumption that GLBA covered them, the October 2025 date arrived without preparation.

Connecticut Follows

Connecticut’s Data Privacy Act (CTDPA) had been in effect since July 2023. Like Montana’s original statute, it included an entity-level GLBA exemption that broadly covered financial institutions. Connecticut’s legislature passed SB 1295, which Governor Lamont signed on June 24, 2025. The amendments took effect July 1, 2026.

Connecticut’s amendment is more detailed than Montana’s in one important way: it retains a narrow entity-level exemption, but only for a specific category of institution. To qualify for Connecticut’s residual entity-level exemption, an organization must be:

  1. A bank or credit union (including affiliates and subsidiaries)
  2. That is only and directly engaged in financial activities as described in the Bank Holding Company Act
  3. That is regulated and examined by the Connecticut Department of Banking or a federal bank regulatory agency
  4. And that has established a program to comply with all applicable requirements

Read those four conditions carefully. A fintech holding a money transmission license does not qualify. A nonbank mortgage servicer does not qualify. An auto dealership with a finance arm does not qualify. An investment adviser that also offers banking products through a third-party bank partnership does not qualify.

What qualifies: a chartered bank or federally-insured credit union doing nothing but banking. The carve-out was written to preserve the status quo for traditional depositories — not to maintain coverage for the broad ecosystem of non-depository financial services companies that operate under GLBA.

Who Is Actually Exposed

The organizations most exposed by these two amendments are the ones that relied on entity-level coverage most heavily:

Fintechs and neobanks. If your firm provides banking or lending services through a bank partner, you are the fintech — not the bank. You are probably subject to GLBA. You almost certainly do not qualify for Connecticut’s narrow residual exemption. If you have customers in Montana or Connecticut, your non-GLBA data is now subject to state privacy law.

Nonbank mortgage companies. Nonbank mortgage servicers and originators are among the most common targets the CFPB has flagged when documenting the gap between GLBA coverage and state privacy law coverage. You collect extensive data — customer contact data for marketing, website behavioral data, email engagement data — that falls outside GLBA’s scope.

Auto dealers with finance operations. Auto dealers subject to GLBA are in the same position. The FTC Safeguards Rule extended to auto dealers in 2023. But Safeguards Rule coverage does not equal state privacy law exemption in Montana or Connecticut.

Investment advisers and broker-dealers. Connecticut’s narrow exemption covers those regulated by the Connecticut Department of Banking or the SEC. The SEC registration piece is significant — investment advisers registered with the SEC may qualify. But advisers whose advisory activities exist alongside other non-financial services activities need to examine whether they meet the “only and directly engaged in financial activities” condition.

Insurance-adjacent financial services. The intersection of GLBA, state insurance regulators, and consumer privacy law is complicated. If your firm has insurance operations alongside banking or lending operations, you need a specific analysis of what exemptions apply to which data.

What You Actually Have to Do

This is not a privacy notice update. Getting into compliance with Montana’s and Connecticut’s privacy laws requires building capability that most GLBA-only programs don’t have.

Step 1: Data inventory for non-GLBA data. Map what your organization collects that isn’t covered by GLBA’s nonpublic personal information definition. Marketing email lists. Website behavioral tracking (cookies, session recording). App analytics. Customer feedback and survey data. Social media data. This inventory is the foundation — you cannot assess your exposure without it.

Step 2: Privacy notice update. Both Montana’s and Connecticut’s laws require a privacy notice that discloses categories of personal information collected, purposes, retention periods, categories of third parties to whom data is shared, and consumer rights. Your existing GLBA privacy notice does not cover this. A standalone state privacy law notice — or an updated comprehensive privacy policy — is required.

Step 3: Consumer rights infrastructure. Montana and Connecticut both give consumers the right to access, correct, delete, and opt out of the sale or sharing of personal information and of targeted advertising. You need a mechanism to receive and respond to these requests within 45 days (with a 45-day extension available). A webform, an email address, and a process for routing and fulfilling requests are the minimum.

Step 4: Processor contracts. State privacy laws require that data processors — vendors who handle personal data on your behalf — operate under written contracts that specify the purpose of processing, limit use to that purpose, require security measures, and give you the right to audit. If your vendor contracts haven’t been reviewed since GLBA was your only framework, they need updating.

California’s ADMT Layer

For organizations with California customers, there’s an additional obligation landing in 2027 that connects to the same data-level exemption logic.

On September 23, 2025, California’s Privacy Protection Agency (CPPA) finalized regulations on automated decision-making technology (ADMT). Starting January 1, 2027, businesses using ADMT to make “significant decisions” affecting consumers — credit underwriting, loan pricing, insurance eligibility, fraud scoring, employment decisions — must provide pre-use notices explaining: how the system works, what the outputs are, the alternative processes available, and how the consumer can exercise their right to opt out.

CCPA’s financial institution exemption has always been a data-level exemption. Data collected in connection with providing a financial product or service may be outside CCPA’s scope. But behavioral data, marketing data, and other non-GLBA data is inside scope — and if your automated decisioning system uses any of that data to inform a significant decision about a California consumer, the ADMT notice and opt-out requirements apply.

The ADMT rules matter for financial services firms in the same way the state privacy law exemption narrowing matters: they assume GLBA covers everything you do. It doesn’t.

We’ve written about how state attorneys general are aggressively filling the gap left by federal agency pullback in consumer protection and fair lending. State privacy law enforcement follows the same pattern. California, Connecticut, and Montana have active enforcement programs — and in California, the CPPA is a fully funded, independent regulator with rulemaking and enforcement authority.

How Many States Are Next?

Twenty states have comprehensive consumer privacy laws as of September 2026. Most of them still use entity-level GLBA exemptions. Montana and Connecticut have shown that these exemptions can be narrowed legislatively without major controversy — the change doesn’t require a privacy law overhaul, just an amendment.

The trend line is toward data-level exemptions. If your organization has been relying on an entity-level exemption in Virginia, Colorado, Texas, or any other state with a comprehensive privacy law, that exemption may not survive the state’s next legislative session unchanged.

Building a data-level compliance capability now — data inventory, consumer rights infrastructure, privacy notices that distinguish GLBA-covered from non-GLBA-covered data — is more durable than building the minimum to comply with any specific state’s current exemption. The minimum keeps moving. The Data Privacy Compliance Kit gives compliance teams the foundational templates to get there.

So What?

If you’re a fintech or nonbank lender with customers in Montana or Connecticut: You have current compliance obligations that started on October 1, 2025 (Montana) and July 1, 2026 (Connecticut). The first step is knowing what data you have outside your GLBA program. The second is building the infrastructure to handle consumer rights requests. Waiting for a regulator to identify the gap is not a strategy.

If you’re a traditional bank with fintech subsidiaries or affiliates: Your bank may qualify for Connecticut’s narrow entity-level exemption. Your fintech subsidiary almost certainly does not. Entity structures built to benefit from entity-level exemptions need to be re-examined under a data-level analysis.

If you’re building your privacy program for the first time: Build for data-level exemptions from the start. Assume that GLBA covers the data collected in connection with your financial products and services, and that everything else is subject to state law. Map what’s in each bucket. Build consumer rights and notice programs for the state law bucket. This is not more work than you’d do if you built for entity-level first and then had to retrofit data-level — and it’s substantially more durable.

If you’re using automated systems for credit, fraud, or eligibility decisions: Pull up California’s ADMT regulations and map which of your decision systems touch California consumers. January 1, 2027 is the compliance date for ADMT significant decisions — you have time, but not unlimited time, to build the pre-use notice and opt-out infrastructure. Read the EU AI Act update for additional context on automated decisioning compliance frameworks.

The GLBA exemption was never a complete answer to state privacy law. In Montana and Connecticut, it is now officially a narrower answer. In other states, it is a narrower answer waiting to happen.


Sources: Orrick, Where is the GLBA Entity-Level Exemption? Two More State Privacy Laws Now Apply to Financial Institutions (2025) | WilmerHale, Connecticut Amends Its Data Privacy Act to Increase Data Protections (July 2026) | Mitchell Sandler, Amended Data Privacy Laws Impact Fintechs, Nonbank Mortgage Companies, and Other Nonbank Financial Services Companies | CFPB, Report Details Carveouts for Financial Institutions in State Data Privacy Laws | CPPA, California Finalizes Regulations to Strengthen Consumers’ Privacy (September 23, 2025)

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the difference between an entity-level and a data-level GLBA exemption?
An entity-level GLBA exemption means that if an organization is a 'financial institution' subject to GLBA, the entire organization — and all the data it holds — is exempt from the state privacy law. A data-level exemption means only the specific data that is actually covered by GLBA (data collected in connection with providing financial products or services) is exempt. Everything else the organization collects — website analytics, marketing data, employment data, non-financial customer information — is subject to the state privacy law.
Which states have narrowed the GLBA exemption for financial institutions?
As of September 2026, Montana and Connecticut are the two states that have amended their comprehensive privacy laws to move from an entity-level GLBA exemption to a narrower data-level exemption. Montana's amendment took effect October 1, 2025. Connecticut's amendment (SB 1295, signed June 24, 2025) took effect July 1, 2026. Other states' laws — including Virginia's VCDPA and Colorado's CPA — contain entity-level GLBA exemptions that have not yet been similarly narrowed.
Who is most affected by the Montana and Connecticut GLBA exemption changes?
The most affected organizations are nonbank financial institutions that are subject to GLBA but are not traditional depository banks or credit unions: fintechs, nonbank mortgage companies, auto dealers with finance arms, peer-to-peer lenders, investment advisers, and certain insurance-adjacent businesses. Connecticut's amendment retains a narrower entity-level exemption only for pure banks and credit unions that are directly regulated by the Connecticut Department of Banking or a federal banking regulator and engage only in BHC Act financial activities. Fintechs and nonbank financial companies do not qualify for this narrow category.
What does a nonbank financial institution need to do if it has customers in Montana or Connecticut?
Four things: (1) Conduct a data inventory to identify what data you collect that falls outside GLBA's scope — marketing data, website behavioral data, loyalty program data, employment data; (2) Build or update your privacy notice to meet state privacy law requirements, including disclosing the categories of personal information collected, purposes, and consumer rights; (3) Implement consumer rights infrastructure to handle opt-out, access, and deletion requests within the required timeframes (45 days under both Montana and Connecticut laws); (4) Review contracts with data processors to ensure they include required provisions under the applicable state law.
Does the GLBA exemption still apply to any data a nonbank financial institution collects?
Yes — at the data level. Under both Montana's and Connecticut's amended laws, data that is actually subject to GLBA (data collected in connection with providing a financial product or service, protected by GLBA's privacy and safeguards rules) is still exempt from the state privacy law. The question is what data a given organization collects that is outside that GLBA-covered scope. For many fintechs and nonbank lenders, the answer is: more than they realize.
How does California's ADMT rule affect financial institutions using automated decisioning?
California's CPPA finalized regulations on automated decision-making technology (ADMT) on September 23, 2025. Starting January 1, 2027, businesses subject to CCPA that use ADMT to make 'significant decisions' about consumers — including credit underwriting, loan pricing, insurance eligibility, or fraud determinations — must provide pre-use notices explaining how the automated system works, what the consumer's alternatives are, and how to exercise the right to opt out. GLBA's financial institution exemption under CCPA is only a data-level exemption (it has been since CCPA's inception), so California's ADMT requirements can apply to data outside GLBA's scope.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.