Skip to main content
ClearValueMoney
Trust6 min read

That Privacy Notice Your Bank Mails You Every Year? Here's What It's Legally Required to Say

GLBA's Regulation P requires banks, credit unions, and brokerages to disclose what they share and let you opt out. Here's what the notice must legally say.

Every year, people who bank, save, or invest get a dense, small-print notice in the mail or their inbox from a bank, credit union, or brokerage — usually titled something like "Privacy Notice" or "Facts About How We Handle Your Personal Information" — and toss it without reading it. That notice isn't marketing, and it isn't optional on the institution's end. It's a legal disclosure required by the Gramm-Leach-Bliley Act (GLBA) and its implementing rule, Regulation P, and it's one of the more useful documents you'll ever ignore — because it's the closest thing you get to a map of exactly what your financial institution collects about you, who it shares it with, and what control you actually have over that.

Here's what the notice is legally required to say, when you're supposed to get one, and why you might not be getting one every year anymore.

When the notice has to show up

Regulation P (codified at 12 CFR Part 1016) requires an initial privacy notice "not later than when the customer relationship is established," per NCUA's own compliance guide to Regulation P. There's a narrow delay allowance: an institution can deliver the notice slightly later only if the relationship wasn't established at the consumer's own election, or if delivering it immediately would substantially delay the transaction and the consumer agrees to get it afterward — and even then, it has to arrive "within a reasonable time."

Beyond the initial notice, institutions generally have to send an annual notice "at least once in any period of 12 consecutive months." That's the version most people are used to seeing land in January or around their account-opening anniversary.

Why you might not get one every year anymore

If you've noticed your bank stopped mailing you an annual privacy notice at some point, that's not necessarily a compliance lapse. A 2015 amendment to Regulation P — often referred to as the FAST Act exception — lets an institution skip the annual notice if two conditions both hold: it only shares your nonpublic personal information under specific narrow exceptions written into GLBA itself (routine sharing for things like processing your transactions or complying with the law), and it hasn't changed its information-sharing policies or practices since the last notice it sent you. If either condition changes — say, the institution starts sharing more broadly, or changes what it discloses — the annual notice requirement comes back.

In practice, that means a lot of "boring," minimal-data-sharing institutions have quietly stopped mailing the annual version, while institutions with broader sharing arrangements (marketing partnerships, affiliate sharing beyond the routine exceptions) generally still have to send one every year.

What the notice is actually required to disclose

When you do get one — initial or annual — Regulation P specifies what has to be in it. Per the same NCUA compliance guide, the notice must cover:

  • What categories of information the institution collects and discloses about you — things like account activity, application information, and information from consumer reporting agencies.
  • What categories of affiliates and outside third parties receive that information.
  • Your opt-out right and how to exercise it — if the institution shares information in ways you can opt out of.
  • The institution's confidentiality and security policies for safeguarding your information.
  • A general statement that the institution shares information with nonaffiliated third parties for "everyday business purposes" — the routine, non-optional sharing (processing transactions, preventing fraud, reporting to credit bureaus, complying with legal requirements) that doesn't trigger an opt-out right at all, because GLBA carves it out as necessary to operating the account.

That last point is worth sitting with: not all sharing described in the notice is something you can turn off. The opt-out right applies to certain categories of sharing — most commonly, sharing with unaffiliated third parties for their own marketing purposes — not to the operational sharing every account requires to function.

How the opt-out actually works

Where an opt-out right does apply, Regulation P requires the institution to explain it "clearly and conspicuously" and to offer at least one reasonable way to exercise it — a check-off box, a reply form, an electronic submission option, or a toll-free number, according to NCUA's guide. You're entitled to "a reasonable opportunity to opt out" before the institution starts sharing your information in the ways the opt-out covers.

One thing worth flagging honestly: the regulation itself doesn't spell out an exact number of days that counts as "reasonable." Different institutions build different windows into their own notices and procedures. If exercising an opt-out matters to you, the fastest way to know your specific timeline is to read the opt-out section of your own institution's notice rather than assume a standard number applies everywhere.

Who this actually applies to

Regulation P covers "financial institutions" as GLBA defines the term — a broad category that includes banks, credit unions, and broker-dealers, among others. Enforcement is split by institution type: NCUA enforces it for federally-insured credit unions specifically, while other financial regulators (including the CFPB, which maintains its own privacy-notices compliance resource for the institutions it oversees) enforce the equivalent requirement for banks, brokerages, and other covered entities under their own jurisdiction.

Why this matters beyond compliance trivia

The privacy notice is, in a narrow but real sense, a trust document — it's the one place an institution is legally required to tell you what it does with your information and what say you have in it. Reading it doesn't take long, and it answers three concrete questions worth knowing for any institution you do business with: what they collect, who else gets it, and whether you actually have a lever to pull if you don't like the answer. It's the same instinct behind checking whether a money site actually discloses how it makes money before trusting its advice — a real disclosure requirement, read carefully, tells you more than a trust badge ever will.

What this isn't

This is a plain-English summary of what Regulation P requires today, not legal advice and not a review of any specific institution's current notice or practices. The exact wording, sharing categories, and opt-out mechanics vary by institution, and the fastest way to know what applies to your own accounts is to read the actual notice your bank, credit union, or brokerage sends you — or ask them directly for a current copy.

Frequently asked

Do I have to get a privacy notice from my bank every single year?

Not necessarily. A 2015 amendment to Regulation P (the FAST Act exception) lets an institution skip the annual notice if it only shares your information under GLBA's routine sharing exceptions and hasn't changed its information-sharing practices since the last notice it sent you. If either condition changes, the annual notice requirement comes back.

Can I stop my bank from sharing my information entirely?

Only where an opt-out right actually applies — typically sharing with unaffiliated third parties for their own marketing purposes. Per Regulation P, routine sharing for "everyday business purposes," like processing your transactions, preventing fraud, or complying with the law, isn't something you can opt out of, because GLBA carves it out as necessary to operating the account.

What is the notice actually required to tell me?

Per NCUA's own Regulation P compliance guide, the notice must disclose the categories of information the institution collects and shares, the categories of parties that receive it, your opt-out right and how to exercise it, and the institution's confidentiality and security policies.

Does this apply to credit unions and brokerages, or just banks?

It applies broadly. GLBA covers "financial institutions" as a category that includes banks, credit unions, and broker-dealers, among others. NCUA enforces the rule for federally-insured credit unions specifically, while other regulators — including the CFPB — enforce the equivalent requirement for the institutions under their own jurisdiction.

Sources

The named, dated public references below back the points made above. Rules and guidance change; confirm the current version with the source before you rely on it.

  1. NCUA — Privacy of Consumer Financial Information (Regulation P)
  2. CFPB — Privacy notices (GLBA)Consumer Financial Protection Bureau

The standard behind this

Everything here traces back to one published editorial standard — how we source, score, and disclose across the family.

New guides

Get an email when we publish new trust coverage.

We're building out the trust shelf. We'll email you the moment new coverage lands — no checking back.

More on trust