GLBA
GLBA: 2024-2025 Pipeline, Coordination and Cross-Mapping to Subordinate Substantive Rules

GLBA GLBA-2024-2025-Pipeline-Section-1033-AI: GLBA 2024-2025 Pipeline - SEC Reg S-P, CFPB Section 1033, NAIC AI Bulletin

GLBA 2024-2025 regulatory pipeline. (a) FTC SAFEGUARDS RULE 30-DAY FTC NOTIFICATION (16 CFR 314.5) - effective 2024-05-13 + applies to security events involving 500+ consumers + 30-day FTC notification + 60-day individual notification + clarifies coordination with state breach notification laws. (b) SEC REGULATION S-P AMENDMENTS - adopted 16 May 2024; effective 2025-12-03 (large institutions over USD 1.5B AUM) + 2026-06-03 (small institutions); new requirements: (1) written incident response program with policies + procedures + records; (2) customer + consumer notification within 30 days of substantial discovery of unauthorized access or use of sensitive customer information; (3) third-party service provider oversight + due diligence + monitoring; (4) extended record-keeping. (c) CFPB SECTION 1033 OPEN BANKING RULE - finalized October 2024 + effective phased 2026-2030; mandates personal-financial-data access via API + screen-scraping prohibition + data-portability + provider authorization + revocation + standardized format; GLBA Safeguarding requirements apply to data recipients + authorized third parties. (d) NAIC MODEL BULLETIN ON AI (December 2023) - 20+ states adopting; insurance-specific AI risk-management + bias testing + explainability + governance. (e) NEW YORK DFS 23 NYCRR 500 (most stringent state cyber rule) AMENDED 2023-11-01 + effective phased through 2025-11-01: enhanced governance + Chief Information Security Officer reporting + 72-hour reporting + ransomware-payment notification + class-A oversight + multi-factor authentication mandate + privileged access management + endpoint detection. (f) FSA CYBERSECURITY BULLETINS - Department of Education FSA increasing scrutiny on Title IV institutions + audit guide enhancements + sector incident notification expectations. (g) EU CSRD ESRS DATA POINTS - cross-border financial institutions face dual GLBA + GDPR/EU NIS2 compliance. (h) SEC CYBERSECURITY DISCLOSURE RULE (Item 1.05 + Item 106) - public-company cybersecurity-event disclosure (separate from GLBA but coordination-relevant for SEC-registered financial institutions).

Other controls in GLBA: 2024-2025 Pipeline, Coordination and Cross-Mapping to Subordinate Substantive Rules

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.