That Privacy Notice Your Bank Mails You Every Year? Here's What It's Legally Required to Say
GLBA's Regulation P requires banks, credit unions, and brokerages to disclose what they share and let you opt out. Here's what the notice must legally say.
Every year, people who bank, save, or invest get a dense, small-print notice in the mail or their inbox from a bank, credit union, or brokerage — usually titled something like "Privacy Notice" or "Facts About How We Handle Your Personal Information" — and toss it without reading it. That notice isn't marketing, and it isn't optional on the institution's end. It's a legal disclosure required by the Gramm-Leach-Bliley Act (GLBA) and its implementing rule, Regulation P, and it's one of the more useful documents you'll ever ignore — because it's the closest thing you get to a map of exactly what your financial institution collects about you, who it shares it with, and what control you actually have over that.
Here's what the notice is legally required to say, when you're supposed to get one, and why you might not be getting one every year anymore.
When the notice has to show up
Regulation P (codified at 12 CFR Part 1016) requires an initial privacy notice "not later than when the customer relationship is established," per NCUA's own compliance guide to Regulation P. There's a narrow delay allowance: an institution can deliver the notice slightly later only if the relationship wasn't established at the consumer's own election, or if delivering it immediately would substantially delay the transaction and the consumer agrees to get it afterward — and even then, it has to arrive "within a reasonable time."
Beyond the initial notice, institutions generally have to send an annual notice "at least once in any period of 12 consecutive months." That's the version most people are used to seeing land in January or around their account-opening anniversary.
Why you might not get one every year anymore
If you've noticed your bank stopped mailing you an annual privacy notice at some point, that's not necessarily a compliance lapse. A 2015 amendment to Regulation P — often referred to as the FAST Act exception — lets an institution skip the annual notice if two conditions both hold: it only shares your nonpublic personal information under specific narrow exceptions written into GLBA itself (routine sharing for things like processing your transactions or complying with the law), and it hasn't changed its information-sharing policies or practices since the last notice it sent you. If either condition changes — say, the institution starts sharing more broadly, or changes what it discloses — the annual notice requirement comes back.
In practice, that means a lot of "boring," minimal-data-sharing institutions have quietly stopped mailing the annual version, while institutions with broader sharing arrangements (marketing partnerships, affiliate sharing beyond the routine exceptions) generally still have to send one every year.
What the notice is actually required to disclose
When you do get one — initial or annual — Regulation P specifies what has to be in it. Per the same NCUA compliance guide, the notice must cover:
- What categories of information the institution collects and discloses about you — things like account activity, application information, and information from consumer reporting agencies.
- What categories of affiliates and outside third parties receive that information.
- Your opt-out right and how to exercise it — if the institution shares information in ways you can opt out of.
- The institution's confidentiality and security policies for safeguarding your information.
- A general statement that the institution shares information with nonaffiliated third parties for "everyday business purposes" — the routine, non-optional sharing (processing transactions, preventing fraud, reporting to credit bureaus, complying with legal requirements) that doesn't trigger an opt-out right at all, because GLBA carves it out as necessary to operating the account.
That last point is worth sitting with: not all sharing described in the notice is something you can turn off. The opt-out right applies to certain categories of sharing — most commonly, sharing with unaffiliated third parties for their own marketing purposes — not to the operational sharing every account requires to function.
How the opt-out actually works
Where an opt-out right does apply, Regulation P requires the institution to explain it "clearly and conspicuously" and to offer at least one reasonable way to exercise it — a check-off box, a reply form, an electronic submission option, or a toll-free number, according to NCUA's guide. You're entitled to "a reasonable opportunity to opt out" before the institution starts sharing your information in the ways the opt-out covers.
One thing worth flagging honestly: the regulation itself doesn't spell out an exact number of days that counts as "reasonable." Different institutions build different windows into their own notices and procedures. If exercising an opt-out matters to you, the fastest way to know your specific timeline is to read the opt-out section of your own institution's notice rather than assume a standard number applies everywhere.
Who this actually applies to
Regulation P covers "financial institutions" as GLBA defines the term — a broad category that includes banks, credit unions, and broker-dealers, among others. Enforcement is split by institution type: NCUA enforces it for federally-insured credit unions specifically, while other financial regulators (including the CFPB, which maintains its own privacy-notices compliance resource for the institutions it oversees) enforce the equivalent requirement for banks, brokerages, and other covered entities under their own jurisdiction.
Why this matters beyond compliance trivia
The privacy notice is, in a narrow but real sense, a trust document — it's the one place an institution is legally required to tell you what it does with your information and what say you have in it. Reading it doesn't take long, and it answers three concrete questions worth knowing for any institution you do business with: what they collect, who else gets it, and whether you actually have a lever to pull if you don't like the answer. It's the same instinct behind checking whether a money site actually discloses how it makes money before trusting its advice — a real disclosure requirement, read carefully, tells you more than a trust badge ever will.
What this isn't
This is a plain-English summary of what Regulation P requires today, not legal advice and not a review of any specific institution's current notice or practices. The exact wording, sharing categories, and opt-out mechanics vary by institution, and the fastest way to know what applies to your own accounts is to read the actual notice your bank, credit union, or brokerage sends you — or ask them directly for a current copy.
Frequently asked
Do I have to get a privacy notice from my bank every single year?
Not necessarily. A 2015 amendment to Regulation P (the FAST Act exception) lets an institution skip the annual notice if it only shares your information under GLBA's routine sharing exceptions and hasn't changed its information-sharing practices since the last notice it sent you. If either condition changes, the annual notice requirement comes back.
Can I stop my bank from sharing my information entirely?
Only where an opt-out right actually applies — typically sharing with unaffiliated third parties for their own marketing purposes. Per Regulation P, routine sharing for "everyday business purposes," like processing your transactions, preventing fraud, or complying with the law, isn't something you can opt out of, because GLBA carves it out as necessary to operating the account.
What is the notice actually required to tell me?
Per NCUA's own Regulation P compliance guide, the notice must disclose the categories of information the institution collects and shares, the categories of parties that receive it, your opt-out right and how to exercise it, and the institution's confidentiality and security policies.
Does this apply to credit unions and brokerages, or just banks?
It applies broadly. GLBA covers "financial institutions" as a category that includes banks, credit unions, and broker-dealers, among others. NCUA enforces the rule for federally-insured credit unions specifically, while other regulators — including the CFPB — enforce the equivalent requirement for the institutions under their own jurisdiction.
Sources
The named, dated public references below back the points made above. Rules and guidance change; confirm the current version with the source before you rely on it.
- NCUA — Privacy of Consumer Financial Information (Regulation P)
- CFPB — Privacy notices (GLBA) — Consumer Financial Protection Bureau
The standard behind this
Everything here traces back to one published editorial standard — how we source, score, and disclose across the family.
Get an email when we publish new trust coverage.
We're building out the trust shelf. We'll email you the moment new coverage lands — no checking back.
More on trust
- If your brokerage failed tomorrow, is your money actually covered? Here's how SIPC protection really works
SIPC covers up to $500,000 per customer ($250,000 cash cap) if a brokerage fails — but not market losses. Here's what's actually protected.
- What's actually in a Form CRS, and how to read yours
SEC's Form CRS explained: what the required two-page disclosure must contain, its 7 conversation-starter questions, and how to use it to compare advisors.
- The FTC's rule against fake reviews, explained: what it bans and what it means for any money site
The FTC's Rule on Consumer Reviews and Testimonials bans fake, bought, and suppressed reviews. Here's what it covers and how to use it to judge any site.