Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

Sensitive Data Under US State Privacy Laws: The GLBA Safe Harbor Fintechs Just Lost — and What to Do Now

Montana and Connecticut just eliminated the GLBA entity-level exemption for non-depository financial institutions, effective October 2025 and July 2026. Here's what 'sensitive data' means across 20+ state laws and what controls you actually need.

By Rebecca Leung · June 12, 2026 ·
Table of Contents

TL;DR:

  • Montana (October 1, 2025) and Connecticut (July 1, 2026) eliminated the GLBA entity-level exemption for non-depository financial institutions — fintechs, nonbank mortgage servicers, and payment companies are now directly in scope for these states’ comprehensive privacy laws.
  • “Sensitive data” means something broader than GLBA’s NPI in every state law that defines it — biometrics, health data, precise geolocation, racial origin, sexual orientation, and financial account credentials paired with access codes are all commonly covered.
  • Most state laws require opt-in consent (not just notice) before processing sensitive data — a meaningfully higher bar than GLBA’s privacy notice and opt-out framework.
  • The states haven’t converged: California’s SPI list, Colorado’s neural data addition, Illinois’s biometric-specific rules, and Texas’s TDPSA definitions all differ. You need a state-by-state map, not a single policy.

Your compliance team has been operating on a reasonable assumption for the last decade: if your company is subject to the Gramm-Leach-Bliley Act, you’re largely exempt from state privacy laws. The exemption was entity-level. You were a financial institution. Done.

Montana’s Attorney General ended that assumption in October 2025.

Montana Senate Bill 297, signed May 8, 2025 and effective October 1, 2025, eliminated the GLBA entity-level exemption from the Montana Consumer Data Privacy Act — for non-depository financial institutions. Fintechs, nonbank mortgage servicers, auto lenders, payment processors, and insurance premium finance companies that thought GLBA covered them in Montana suddenly found themselves subject to a state privacy law with opt-in consent requirements for sensitive data, data subject rights workflows, and a mandatory data protection assessment process.

Connecticut followed in June 2025 with Senate Bill 1295 — effective July 1, 2026. Same structure: entity-level exemption gone for non-banks, data-level exemption preserved, thresholds lowered to 35,000 consumers (from 100,000), and new requirements that explicitly target sensitive data processing.

This is not a Montana-and-Connecticut problem. This is a template. The legal community watching these amendments is already asking which state adopts it next.

What “Sensitive Data” Actually Means — and Why It’s Not GLBA NPI

GLBA’s Nonpublic Personal Information definition is narrow by design. It covers personally identifiable financial information you receive from a consumer in connection with providing a financial product or service. A mortgage application. A bank account opening. A payment transaction.

State privacy laws define “sensitive data” in ways that go significantly further — and the definitions aren’t consistent across states.

CategoryCPRA (CA)Colorado CPATexas TDPSAIllinois BIPAMontana MCDPA
Biometric data✓ SPI✓ Sensitive✓ Sensitive✓ (dedicated law)✓ Sensitive
Health/medical data✓ SPI✓ Sensitive✓ Sensitive✓ Sensitive
Precise geolocation✓ SPI✓ Sensitive✓ Sensitive✓ Sensitive
Racial/ethnic origin✓ SPI✓ Sensitive✓ Sensitive✓ Sensitive
Sexual orientation✓ SPI✓ Sensitive✓ Sensitive✓ Sensitive
Financial account + credentials✓ SPI✓ Sensitive
Religious beliefs✓ SPI✓ Sensitive✓ Sensitive✓ Sensitive
Genetic data✓ SPI✓ Sensitive✓ Sensitive
Neural data✓ Sensitive (2025)
Union membership✓ SPI✓ Sensitive

The data that falls outside GLBA NPI but inside these sensitive data definitions is exactly where fintechs are exposed. Employee data. Marketing prospect data. Website behavioral data linked to demographic inference. App usage patterns. The customer list you bought from a data broker that includes health indicators.

None of that is GLBA NPI. All of it can trigger state law requirements.

The Entity-Level vs. Data-Level Distinction Matters

Before Montana and Connecticut moved, the GLBA exemption structure in most state privacy laws worked like this:

Entity-level exemption: If your company is a “financial institution” subject to GLBA, the entire state privacy law doesn’t apply to your company or any data it processes. You’re out of scope entirely.

Data-level exemption: Only the specific data your company processes “pursuant to” GLBA — NPI from financial product and service relationships — is exempt. Everything else the state law covers, it covers.

Montana and Connecticut kept the data-level exemption intact. The NPI from your mortgage originations, your payment processing relationships, your bank accounts is still exempt. But they stripped the entity-level shield for non-depository financial institutions. If you’re not a state or federally chartered bank or credit union, your company is no longer automatically out of scope.

The practical impact: a nonbank mortgage servicer in Montana must now comply with the MCDPA for:

  • Employee personal data (HR records, workforce monitoring)
  • Marketing prospect lists and email engagement data
  • Website visitor data (analytics, tracking pixels, behavioral targeting)
  • Data collected from people who visited your site but never became customers
  • Any sensitive data that isn’t NPI from an active financial relationship

Montana SB 297: What Changed October 1, 2025

SB 297 amended the MCDPA in three ways that matter for financial services:

1. Exemption restructure: The financial institution exemption now covers only banks and credit unions (state or federally chartered) and their affiliates. Non-depository GLBA-covered entities are out.

2. Lower applicability thresholds: SB 297 dropped the threshold from 50,000 consumers to 25,000 consumers, and from 25,000 consumers (with 25%+ revenue from data sales) to 15,000 consumers. More companies qualify.

3. Sensitive data consent shift: Processing sensitive data requires opt-in consent from the consumer. This is not GLBA’s opt-out framework — it’s an affirmative consent requirement before processing.

If you process personal data about 25,000 or more Montana consumers and you’re not a depository institution, you’ve been subject to the MCDPA since October 1, 2025.

Connecticut SB 1295: What Changes July 1, 2026

Connecticut’s amendments, signed June 24, 2025 and effective July 1, 2026, follow the same pattern with additional reach:

1. GLBA exemption restructure: Same as Montana — entity-level exemption removed for non-bank financial institutions, data-level exemption preserved. Banks and credit unions are still out. Fintechs, payment companies, and nonbank lenders are in scope.

2. Threshold reduction: CDPA now applies to companies processing personal data about 35,000 or more Connecticut residents (down from 100,000), or selling personal data about even one Connecticut resident.

3. Sensitive data controls: Processing sensitive data requires a Data Protection Assessment and either opt-in consent (for processing personal data) or a clear opt-out mechanism (for targeted advertising using sensitive data).

4. Enforcement posture: Connecticut’s AG has been active — and the lower thresholds plus eliminated exemption will bring significantly more financial services companies into scope for examination.

Who’s Exposed: The Risk Matrix

Not all financial services companies face the same exposure under this shift.

Highest risk:

  • Nonbank mortgage servicers and originators operating in Montana or Connecticut
  • Fintech lenders with marketing data operations (prospect lists, retargeting)
  • Payment processors that collect behavioral data from merchant analytics
  • Insurance companies that are GLBA-covered but not depository institutions

Moderate risk:

  • BaaS platforms collecting partner fintech customer data
  • Wealth management firms with non-NPI marketing databases
  • Embedded finance providers collecting e-commerce behavioral data

Lower risk (but not zero):

  • Depository institutions (banks and credit unions retain entity-level exemptions in Montana and Connecticut)
  • Companies with no Montana or Connecticut consumer relationships

Key gap to check: Your marketing database. If your team is running retargeting campaigns, email nurture sequences, or behavioral personalization on consumers who never became customers — that data isn’t GLBA NPI, and it may include sensitive data categories (health inference, geolocation, demographic targeting based on race proxies). That’s exactly what these laws target.

What Sensitive Data Controls Actually Require

Most state privacy laws impose four categories of requirements when you process sensitive data:

GLBA requires you to provide a privacy notice and offer an opt-out from sharing NPI with non-affiliated third parties. State laws flip this for sensitive data — you need affirmative opt-in consent before processing. Montana, Connecticut, Virginia, Colorado, and Texas all require opt-in for sensitive data categories including biometrics and health data.

This matters most for biometric data (face scans in banking app authentication, fingerprints for vault access) and health data (wellness incentive programs, FSA eligibility data, health indicator data used in underwriting proxies).

2. Purpose Limitation

You can only use sensitive data for the purpose you disclosed when you collected consent. Using biometric verification data to train a different fraud model without re-disclosure violates purpose limitation. This requires your privacy notices to be specific — “biometric data collected for identity verification” doesn’t cover “biometric data used to train our authentication model.”

3. Data Protection Assessment / DPIA

Before initiating sensitive data processing activities, most state laws require a documented assessment covering the purpose of processing, the necessity of sensitive data, alternatives considered, and the risks to consumers. California’s CPPA cybersecurity audit requirement adds a layer: businesses that process SPI must conduct a cybersecurity audit that covers sensitive data handling. Colorado requires a DPIA for processing sensitive data at scale.

4. Consumer Rights Execution

Individuals have the right to know what sensitive data you hold, correct it, delete it, and in most states, opt out of sale. Your DSAR response workflow needs to handle sensitive data categories specifically — not just generic data subject requests.

The DSAR response workflow that works for general personal data needs a sensitive data lane: faster response timelines, more senior approval for denials, and documentation of the basis for retention if you decline to delete.

What Isn’t Covered by This Post

The sensitive data framework described here is separate from biometric-specific laws. Illinois BIPA, Texas CUBI, and similar statutes have their own consent, retention, and destruction requirements that go beyond general sensitive data treatment. If you’re collecting facial recognition, fingerprints, or voiceprints, you need a separate BIPA-and-CUBI compliance analysis — see our biometric privacy compliance guide for that layer.

The Texas TDPSA GLBA exemption question — which follows a different analytical path from Montana and Connecticut — is covered separately in our Texas TDPSA financial services analysis.

So What? Five Steps Before July 1, 2026

If you’re a non-depository financial institution with consumers in Montana or Connecticut, here’s the triage:

1. Map your consumer data by geography and category. Pull your CRM and analytics data for Montana and Connecticut consumers. Separate NPI from financial product relationships (likely still exempt as data-level) from everything else (likely in scope).

2. Identify sensitive data categories in your non-NPI processing. Does your marketing database include health or demographic data? Does your mobile app collect precise geolocation? Does your authentication system use biometrics? Each category triggers heightened controls.

3. Audit your consent mechanisms. GLBA’s privacy notice doesn’t satisfy state opt-in consent requirements for sensitive data. If you’re processing sensitive non-NPI data from Montana or Connecticut consumers, you need affirmative consent mechanisms.

4. Run a Data Protection Assessment. Before July 1 for Connecticut; ideally now for Montana. Document why you’re processing sensitive data, what alternatives exist, and what risks it creates.

5. Update your DSAR workflow. Make sure your consumer request process covers Montana and Connecticut consumers, includes sensitive data deletion as a category, and has response timelines mapped to each state’s requirements.

Our earlier analysis on state privacy laws and the GLBA safe harbor covers the broader landscape before Montana and Connecticut moved. The picture has shifted materially since that post — the entity-level exemption is no longer reliable for non-depository institutions in these two states, and that trend will continue.

For teams building or updating a state privacy compliance program, the Data Privacy Compliance Kit includes a 19-state applicability matrix, DSAR workflow, consent management framework, and data protection assessment template — updated for the Montana and Connecticut changes.

The GLBA blanket kept you warm for a long time. Fold it carefully — it still covers NPI — but don’t assume it covers everything anymore.


Sources: Orrick: Where is the GLBA Entity-Level Exemption?, Perkins Coie: Montana SB 297 Analysis, Perkins Coie: Connecticut Pierces the GLBA Veil, Baird Holm: Two States Limit GLBA Exemptions, MultiState: 20 State Privacy Laws in Effect in 2026

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Which state privacy laws still exempt financial institutions subject to GLBA?
As of mid-2026, most states with comprehensive privacy laws still have a GLBA entity-level exemption for financial institutions — but the trend is moving fast toward data-level-only exemptions. Montana (effective October 1, 2025) and Connecticut (effective July 1, 2026) have already eliminated the entity-level exemption for non-depository financial institutions, meaning fintechs, nonbank mortgage servicers, and payment companies are now in scope. Indiana, Kentucky, and Rhode Island (all effective January 1, 2026) have GLBA entity-level exemptions that still apply. The safest approach is to assume the exemption will narrow and build a data-level compliance posture now.
What is 'sensitive data' under state privacy laws and how does it differ from GLBA NPI?
GLBA's Nonpublic Personal Information (NPI) definition is narrow: personally identifiable financial information you receive in connection with a financial product or service. State privacy laws define 'sensitive data' much more broadly. CPRA's Sensitive Personal Information (SPI) includes biometrics, health data, precise geolocation, racial/ethnic origin, religious beliefs, union membership, genetic data, sexual orientation, and — critically — financial account numbers combined with access credentials. Colorado added neural data in 2025. Texas TDPSA covers health data and biometrics. The data that falls outside GLBA NPI but inside state sensitive data definitions — employee data, marketing prospect data, website behavior tied to demographics — is exactly where fintechs are exposed.
What controls are required for sensitive data under state privacy laws?
Most state laws with sensitive data categories require: (1) opt-in consent before processing (stronger than GLBA's opt-out for NPI sharing), (2) purpose limitation — you can only use sensitive data for the disclosed purpose, (3) data minimization — collect only what's necessary, (4) a data protection assessment / DPIA before initiating sensitive data processing, and (5) the right to request deletion and opt out of sales. Some states add specific requirements: Illinois BIPA requires a written retention schedule and destruction policy for biometrics. California CPRA requires a separate opt-out mechanism for sharing SPI. Connecticut requires DPIAs for high-risk processing including sensitive data.
What is the difference between an entity-level and data-level GLBA exemption?
An entity-level exemption means that if your company is subject to GLBA, the entire state privacy law doesn't apply to your company. A data-level exemption means only the specific data that's already protected by GLBA is exempt — everything else the state privacy law covers. Montana SB 297 and Connecticut SB 1295 both shifted to data-level exemptions for non-depository financial institutions. A nonbank mortgage servicer in Montana must now comply with the MCDPA for any personal data it processes that isn't GLBA-covered NPI — which includes marketing prospect data, employee data, and website visitor data.
Does the CPRA 'Sensitive Personal Information' category apply to financial institutions?
CCPA/CPRA has always had a GLBA exemption — but it's a data-level exemption. California's exemption applies to personal information 'collected, processed, sold, or disclosed pursuant to' GLBA. Any consumer data you collect that isn't directly tied to a financial product or service — website behavioral data, email marketing lists, social media interactions — is potentially in scope for CPRA's SPI requirements. The California Privacy Protection Agency's cybersecurity audit requirement (which began in 2026) applies to businesses that process SPI, and the lower applicability thresholds from the 2025 CPPA rulemaking mean more financial services companies qualify than before.
Which states have the strictest penalties for mishandling sensitive data?
Illinois BIPA remains the highest-risk for biometric data: $1,000 per negligent violation, $5,000 per intentional violation, and a private right of action that has produced class action settlements in the tens of millions. California imposes up to $7,500 per intentional violation, with the CPPA's Enforcement Division now actively investigating after issuing enforcement notices. Texas TDPSA allows the AG to recover up to $7,500 per violation. Connecticut allows up to $5,000 per violation. Illinois uniquely has no required cure period for BIPA — you can be sued without prior notice.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.