Back to the hub

CCPA GLBA exemption: does the CCPA apply to financial institutions?

Cal. Civ. Code 1798.145(e) exempts personal information collected, processed, sold or disclosed subject to the Gramm-Leach-Bliley Act and its regulations, the California Financial Information Privacy Act, or the Farm Credit Act. The exemption covers data, not the company, and expressly does not apply to Section 1798.150 breach claims.

Applies to: Financial institutions, lenders, insurers, fintechs and any CCPA-covered business that handles some personal information regulated by the Gramm-Leach-Bliley Act alongside personal information that is not.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Financial-services teams often read one line about a GLBA carve-out and conclude the CCPA does not apply to them. That conclusion is usually wrong, and the way it is wrong is expensive. California wrote its exemption around data, not around companies, and it deliberately left the breach lawsuit provision outside the carve-out.

What Section 1798.145(e) actually says

The text is narrow and specific. This title shall not apply to personal information collected, processed, sold, or disclosed subject to the federal Gramm-Leach-Bliley Act and implementing regulations, or the California Financial Information Privacy Act, or the federal Farm Credit Act of 1971. Then one more sentence: this subdivision shall not apply to Section 1798.150.

Read the subject of that sentence. It is "personal information", not "a financial institution". Nothing in Section 1798.145(e) exempts an entity. The moment a data set falls outside GLBA's reach, the CCPA applies to it in full.

The entity-level comparison that makes this obvious

Other states wrote the same idea differently, and the contrast is the clearest way to see what California did. Nebraska exempts, at Neb. Rev. Stat. Section 87-1103(2)(b), any "financial institution, affiliate of a financial institution, or data subject to Title V of the Gramm-Leach-Bliley Act". Indiana does the same at IC 24-15-1-1(b)(2), and Iowa at Iowa Code Section 715D.2(2). Those statutes name the institution first and the data second, so a covered bank is out of scope in those states entirely.

California names only the data. A bank operating in both California and Iowa can be wholly outside the Iowa act and squarely inside the CCPA for the same corporate entity.

Which of your data is not GLBA data

In practice the gap is larger than teams expect. GLBA reaches nonpublic personal information about consumers obtained in connection with providing a financial product or service. It does not obviously reach:

  • Visitors to your marketing site who never applied for anything, including advertising and analytics identifiers.
  • Prospects and leads bought from a list who never became customers.
  • Job applicants and contractors, which California brought fully into the CCPA.
  • Business contacts at commercial counterparties, to the extent they act in an individual capacity.

Each of those categories carries the full set of CCPA rights: know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information.

The breach lawsuit is expressly not exempt

The final sentence of Section 1798.145(e) is the one that matters most for risk. By excluding Section 1798.150 from the exemption, California kept GLBA-regulated data inside the private right of action. If unencrypted and unredacted personal information is exfiltrated because reasonable security was missing, a consumer can sue, and the statutory damages range is set by the California Privacy Protection Agency's inflation adjustment at $107 to $799 per consumer per incident, or actual damages if higher. For a breach touching a large customer file, that arithmetic gets serious quickly, and the GLBA exemption does not touch it.

Where this leaves you

Treat the GLBA exemption as a filter you apply data set by data set, not a status you claim once. Start by confirming the CCPA applies to your business at all under California's thresholds, then map the boundary, then run the remaining data through the ordinary CCPA exemption analysis.

Next step

If you hold a mix of GLBA-regulated and ordinary personal information, the free 2-minute Obligation Scan works out whether the CCPA reaches your business and which data sets the exemption does not cover, so the gap does not surface for the first time in a breach claim. The US state privacy laws hub shows how California's data-level approach compares with the entity-level exemptions elsewhere.

Compliance checklist

  • Map which of your data sets are genuinely collected, processed, sold or disclosed subject to GLBA and its implementing regulations, rather than assuming the whole company is out of scope.
  • Treat everything outside that boundary, including website analytics, prospect data, and applicant data, as ordinary CCPA personal information with full consumer rights attached.
  • Confirm whether you also fall under the California Financial Information Privacy Act or the federal Farm Credit Act, which Section 1798.145(e) exempts on the same terms.
  • Keep reasonable security in place for GLBA data anyway, because Section 1798.145(e) does not exempt it from the Section 1798.150 private right of action.
  • Check your CCPA applicability separately under Cal. Civ. Code Section 1798.140(d): the exemption narrows what the Act reaches, it does not decide whether the Act reaches you.

Sources

Last verified: 2026-09-02

Informational, not legal advice.