Feature Data Privacy
Sensitive Data Under US State Privacy Laws: The GLBA Safe Harbor Fintechs Just Lost — and What to Do Now
Montana and Connecticut just eliminated the GLBA entity-level exemption for non-depository financial institutions, effective October 2025 and July 2026. Here's what 'sensitive data' means across 20+ state laws and what controls you actually need.
Table of Contents
TL;DR:
- Montana (October 1, 2025) and Connecticut (July 1, 2026) eliminated the GLBA entity-level exemption for non-depository financial institutions — fintechs, nonbank mortgage servicers, and payment companies are now directly in scope for these states’ comprehensive privacy laws.
- “Sensitive data” means something broader than GLBA’s NPI in every state law that defines it — biometrics, health data, precise geolocation, racial origin, sexual orientation, and financial account credentials paired with access codes are all commonly covered.
- Most state laws require opt-in consent (not just notice) before processing sensitive data — a meaningfully higher bar than GLBA’s privacy notice and opt-out framework.
- The states haven’t converged: California’s SPI list, Colorado’s neural data addition, Illinois’s biometric-specific rules, and Texas’s TDPSA definitions all differ. You need a state-by-state map, not a single policy.
Your compliance team has been operating on a reasonable assumption for the last decade: if your company is subject to the Gramm-Leach-Bliley Act, you’re largely exempt from state privacy laws. The exemption was entity-level. You were a financial institution. Done.
Montana’s Attorney General ended that assumption in October 2025.
Montana Senate Bill 297, signed May 8, 2025 and effective October 1, 2025, eliminated the GLBA entity-level exemption from the Montana Consumer Data Privacy Act — for non-depository financial institutions. Fintechs, nonbank mortgage servicers, auto lenders, payment processors, and insurance premium finance companies that thought GLBA covered them in Montana suddenly found themselves subject to a state privacy law with opt-in consent requirements for sensitive data, data subject rights workflows, and a mandatory data protection assessment process.
Connecticut followed in June 2025 with Senate Bill 1295 — effective July 1, 2026. Same structure: entity-level exemption gone for non-banks, data-level exemption preserved, thresholds lowered to 35,000 consumers (from 100,000), and new requirements that explicitly target sensitive data processing.
This is not a Montana-and-Connecticut problem. This is a template. The legal community watching these amendments is already asking which state adopts it next.
What “Sensitive Data” Actually Means — and Why It’s Not GLBA NPI
GLBA’s Nonpublic Personal Information definition is narrow by design. It covers personally identifiable financial information you receive from a consumer in connection with providing a financial product or service. A mortgage application. A bank account opening. A payment transaction.
State privacy laws define “sensitive data” in ways that go significantly further — and the definitions aren’t consistent across states.
| Category | CPRA (CA) | Colorado CPA | Texas TDPSA | Illinois BIPA | Montana MCDPA |
|---|---|---|---|---|---|
| Biometric data | ✓ SPI | ✓ Sensitive | ✓ Sensitive | ✓ (dedicated law) | ✓ Sensitive |
| Health/medical data | ✓ SPI | ✓ Sensitive | ✓ Sensitive | — | ✓ Sensitive |
| Precise geolocation | ✓ SPI | ✓ Sensitive | ✓ Sensitive | — | ✓ Sensitive |
| Racial/ethnic origin | ✓ SPI | ✓ Sensitive | ✓ Sensitive | — | ✓ Sensitive |
| Sexual orientation | ✓ SPI | ✓ Sensitive | ✓ Sensitive | — | ✓ Sensitive |
| Financial account + credentials | ✓ SPI | ✓ Sensitive | — | — | — |
| Religious beliefs | ✓ SPI | ✓ Sensitive | ✓ Sensitive | — | ✓ Sensitive |
| Genetic data | ✓ SPI | ✓ Sensitive | ✓ Sensitive | — | — |
| Neural data | — | ✓ Sensitive (2025) | — | — | — |
| Union membership | ✓ SPI | ✓ Sensitive | — | — | — |
The data that falls outside GLBA NPI but inside these sensitive data definitions is exactly where fintechs are exposed. Employee data. Marketing prospect data. Website behavioral data linked to demographic inference. App usage patterns. The customer list you bought from a data broker that includes health indicators.
None of that is GLBA NPI. All of it can trigger state law requirements.
The Entity-Level vs. Data-Level Distinction Matters
Before Montana and Connecticut moved, the GLBA exemption structure in most state privacy laws worked like this:
Entity-level exemption: If your company is a “financial institution” subject to GLBA, the entire state privacy law doesn’t apply to your company or any data it processes. You’re out of scope entirely.
Data-level exemption: Only the specific data your company processes “pursuant to” GLBA — NPI from financial product and service relationships — is exempt. Everything else the state law covers, it covers.
Montana and Connecticut kept the data-level exemption intact. The NPI from your mortgage originations, your payment processing relationships, your bank accounts is still exempt. But they stripped the entity-level shield for non-depository financial institutions. If you’re not a state or federally chartered bank or credit union, your company is no longer automatically out of scope.
The practical impact: a nonbank mortgage servicer in Montana must now comply with the MCDPA for:
- Employee personal data (HR records, workforce monitoring)
- Marketing prospect lists and email engagement data
- Website visitor data (analytics, tracking pixels, behavioral targeting)
- Data collected from people who visited your site but never became customers
- Any sensitive data that isn’t NPI from an active financial relationship
Montana SB 297: What Changed October 1, 2025
SB 297 amended the MCDPA in three ways that matter for financial services:
1. Exemption restructure: The financial institution exemption now covers only banks and credit unions (state or federally chartered) and their affiliates. Non-depository GLBA-covered entities are out.
2. Lower applicability thresholds: SB 297 dropped the threshold from 50,000 consumers to 25,000 consumers, and from 25,000 consumers (with 25%+ revenue from data sales) to 15,000 consumers. More companies qualify.
3. Sensitive data consent shift: Processing sensitive data requires opt-in consent from the consumer. This is not GLBA’s opt-out framework — it’s an affirmative consent requirement before processing.
If you process personal data about 25,000 or more Montana consumers and you’re not a depository institution, you’ve been subject to the MCDPA since October 1, 2025.
Connecticut SB 1295: What Changes July 1, 2026
Connecticut’s amendments, signed June 24, 2025 and effective July 1, 2026, follow the same pattern with additional reach:
1. GLBA exemption restructure: Same as Montana — entity-level exemption removed for non-bank financial institutions, data-level exemption preserved. Banks and credit unions are still out. Fintechs, payment companies, and nonbank lenders are in scope.
2. Threshold reduction: CDPA now applies to companies processing personal data about 35,000 or more Connecticut residents (down from 100,000), or selling personal data about even one Connecticut resident.
3. Sensitive data controls: Processing sensitive data requires a Data Protection Assessment and either opt-in consent (for processing personal data) or a clear opt-out mechanism (for targeted advertising using sensitive data).
4. Enforcement posture: Connecticut’s AG has been active — and the lower thresholds plus eliminated exemption will bring significantly more financial services companies into scope for examination.
Who’s Exposed: The Risk Matrix
Not all financial services companies face the same exposure under this shift.
Highest risk:
- Nonbank mortgage servicers and originators operating in Montana or Connecticut
- Fintech lenders with marketing data operations (prospect lists, retargeting)
- Payment processors that collect behavioral data from merchant analytics
- Insurance companies that are GLBA-covered but not depository institutions
Moderate risk:
- BaaS platforms collecting partner fintech customer data
- Wealth management firms with non-NPI marketing databases
- Embedded finance providers collecting e-commerce behavioral data
Lower risk (but not zero):
- Depository institutions (banks and credit unions retain entity-level exemptions in Montana and Connecticut)
- Companies with no Montana or Connecticut consumer relationships
Key gap to check: Your marketing database. If your team is running retargeting campaigns, email nurture sequences, or behavioral personalization on consumers who never became customers — that data isn’t GLBA NPI, and it may include sensitive data categories (health inference, geolocation, demographic targeting based on race proxies). That’s exactly what these laws target.
What Sensitive Data Controls Actually Require
Most state privacy laws impose four categories of requirements when you process sensitive data:
1. Opt-In Consent (Not Notice)
GLBA requires you to provide a privacy notice and offer an opt-out from sharing NPI with non-affiliated third parties. State laws flip this for sensitive data — you need affirmative opt-in consent before processing. Montana, Connecticut, Virginia, Colorado, and Texas all require opt-in for sensitive data categories including biometrics and health data.
This matters most for biometric data (face scans in banking app authentication, fingerprints for vault access) and health data (wellness incentive programs, FSA eligibility data, health indicator data used in underwriting proxies).
2. Purpose Limitation
You can only use sensitive data for the purpose you disclosed when you collected consent. Using biometric verification data to train a different fraud model without re-disclosure violates purpose limitation. This requires your privacy notices to be specific — “biometric data collected for identity verification” doesn’t cover “biometric data used to train our authentication model.”
3. Data Protection Assessment / DPIA
Before initiating sensitive data processing activities, most state laws require a documented assessment covering the purpose of processing, the necessity of sensitive data, alternatives considered, and the risks to consumers. California’s CPPA cybersecurity audit requirement adds a layer: businesses that process SPI must conduct a cybersecurity audit that covers sensitive data handling. Colorado requires a DPIA for processing sensitive data at scale.
4. Consumer Rights Execution
Individuals have the right to know what sensitive data you hold, correct it, delete it, and in most states, opt out of sale. Your DSAR response workflow needs to handle sensitive data categories specifically — not just generic data subject requests.
The DSAR response workflow that works for general personal data needs a sensitive data lane: faster response timelines, more senior approval for denials, and documentation of the basis for retention if you decline to delete.
What Isn’t Covered by This Post
The sensitive data framework described here is separate from biometric-specific laws. Illinois BIPA, Texas CUBI, and similar statutes have their own consent, retention, and destruction requirements that go beyond general sensitive data treatment. If you’re collecting facial recognition, fingerprints, or voiceprints, you need a separate BIPA-and-CUBI compliance analysis — see our biometric privacy compliance guide for that layer.
The Texas TDPSA GLBA exemption question — which follows a different analytical path from Montana and Connecticut — is covered separately in our Texas TDPSA financial services analysis.
So What? Five Steps Before July 1, 2026
If you’re a non-depository financial institution with consumers in Montana or Connecticut, here’s the triage:
1. Map your consumer data by geography and category. Pull your CRM and analytics data for Montana and Connecticut consumers. Separate NPI from financial product relationships (likely still exempt as data-level) from everything else (likely in scope).
2. Identify sensitive data categories in your non-NPI processing. Does your marketing database include health or demographic data? Does your mobile app collect precise geolocation? Does your authentication system use biometrics? Each category triggers heightened controls.
3. Audit your consent mechanisms. GLBA’s privacy notice doesn’t satisfy state opt-in consent requirements for sensitive data. If you’re processing sensitive non-NPI data from Montana or Connecticut consumers, you need affirmative consent mechanisms.
4. Run a Data Protection Assessment. Before July 1 for Connecticut; ideally now for Montana. Document why you’re processing sensitive data, what alternatives exist, and what risks it creates.
5. Update your DSAR workflow. Make sure your consumer request process covers Montana and Connecticut consumers, includes sensitive data deletion as a category, and has response timelines mapped to each state’s requirements.
Our earlier analysis on state privacy laws and the GLBA safe harbor covers the broader landscape before Montana and Connecticut moved. The picture has shifted materially since that post — the entity-level exemption is no longer reliable for non-depository institutions in these two states, and that trend will continue.
For teams building or updating a state privacy compliance program, the Data Privacy Compliance Kit includes a 19-state applicability matrix, DSAR workflow, consent management framework, and data protection assessment template — updated for the Montana and Connecticut changes.
The GLBA blanket kept you warm for a long time. Fold it carefully — it still covers NPI — but don’t assume it covers everything anymore.
Sources: Orrick: Where is the GLBA Entity-Level Exemption?, Perkins Coie: Montana SB 297 Analysis, Perkins Coie: Connecticut Pierces the GLBA Veil, Baird Holm: Two States Limit GLBA Exemptions, MultiState: 20 State Privacy Laws in Effect in 2026
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Which state privacy laws still exempt financial institutions subject to GLBA?
What is 'sensitive data' under state privacy laws and how does it differ from GLBA NPI?
What controls are required for sensitive data under state privacy laws?
What is the difference between an entity-level and data-level GLBA exemption?
Does the CPRA 'Sensitive Personal Information' category apply to financial institutions?
Which states have the strictest penalties for mishandling sensitive data?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Jul 15, 2026