(BOSTON 4/8/2026) — The National Conference of State Legislatures recently sent a bipartisan letter calling on DC lawmakers to change course on a draft bill eliminating states’ ability to draft financial privacy and data security regulations that exceed federal standards. The bill, meant as an update to the Gramm-Leach-Bliley Act (GLBA), would amend Section 507 to preempt any state-level law that establishes privacy or security regulations for financial institutions subject to GLBA – even when those laws strengthen protections for consumers. The letter is addressed to Representative French Hill (R-AR), Chair of the House Financial Services Committee, and to Representative Maxine Waters (D-CA), the Committee’s Ranking Member.
“Massachusetts’ nation-leading consumer protection laws are no accident – they are the product of decades of advocacy, research, and accountability for corporations that have played fast and loose with the private information of everyday Bay Staters. The update to the GLBA that Congress is currently drafting would undermine that work and strip states of the tools we need to defend consumers against bad actors, whether they are greedy financial corporations or cybercriminals looking to steal sensitive data,” said Senator Michael Moore (D-Millbury). “As the chair of the Massachusetts Legislature’s top tech committee, the vice chair of its top finance committee, and the co-chair of the NCSL’s banking committee, this action stands at the intersection of the issues that are most important to me. The GLBA was intended from its conception to establish minimum data protection standards for banks, credit unions, and lenders; by preempting state laws, Republican majorities in Congress are effectively loosening these standards. I stand with the NCSL as they ask DC to reconsider this action. And if they don’t? Ask yourself – who does that benefit?”
The GLBA was passed in 1999 and signed into law by President Bill Clinton. Its most splashy policy change at the time was a relaxation of the Depression-era Glass-Steagall Act rules that legalized mega-mergers between investment banks, commercial banks, and insurance companies. But another critical piece – the policy most relevant when discussing the GLBA today – is its establishment of a three-pronged approach to protecting the sensitive consumer data collected by the institutions Americans bank with, receive loans from, and invest through. Its ‘pretexting provision’ bans the solicitation and disclosure of personal data by false pretenses; the ‘financial privacy rule’ requires that a financial institution provide written privacy policies to its customers; and the ‘safeguards rule’ requires institutions regularly assess internal and external risks to customer data and implement comprehensive security programs to keep its data safe. Critically, these provisions established minimum rules, allowing states to go beyond them if their legislatures chose to do so.
In the years since its passage, several states have written rules that go further than the GLBA’s data privacy protections, most notably California. America’s most populated state and amongst the world’s largest economies, California’s standard effectively became the nation’s standard after its passage, broadening the scope of data covered by the law, reversing the GLBA’s data sharing opt-out provision to require an explicit opt-in if an institution wishes to share a consumer’s data, allowing California residents to sue financial institutions for certain data breaches, and more. While not written into law in most states, many of these stricter standards are extended nationwide to simplify a covered financial institution’s compliance and legal exposure.
Despite over 20 years of these regulations being in place, Congress – with GOP majorities in both chambers – has decided to include a preemption clause in an update to the GLBA it is currently drafting. Republicans argue that allowing states to go above and beyond the law’s baseline standards create a fragmented regulatory environment, but the NCSL letter argues that these concerns are overstated and don’t capture the reality of how states and institutions have acted over the past two decades. The letter states, “In practice, state financial privacy and data security laws have increasingly converged around core principles, including reasonable data security obligations, limits on use and sharing of sensitive financial data and strong enforcement by state regulators. Many businesses already mitigate compliance burdens by aligning their practices with the highest applicable standards across jurisdictions, rather than tailoring policies on a state-by-state basis.”
States have proven that they can act faster and are more responsive to cybersecurity and data privacy risks than Congress, the letter argues. “An inflexible across-the-board preemption of state authority would freeze consumer financial privacy standards in statute, stifle innovation and prevent states from responding to unforeseen harms, including data breaches, misuse of biometric or geolocation data and risks arising from new financial technologies and artificial intelligence.”
Privacy and consumer protection laws have a long precedent for acting as a minimum standard, as the GLBA has. HIPAA, FERPA, and COPPA are settled in law as a regulatory floor just as the GLBA has been until recently, the letter states. It argues that states should retain the long-held authority to respond to risks that uniquely affect their residents and financial markets.
“We respectfully urge the committee to reconsider the scope of the draft’s preemption language and to restore GLBA’s traditional balance between national standards and state authority. NCSL and state legislators stand ready to work with the committee to strengthen consumer financial privacy and security while respecting the essential role states play in protecting residents, overseeing markets and responding to emerging risks,” the letter closes.
The proposed language preempting state laws on GLBA regulations continues a pattern of DC considering revoking or following through on revoking state regulatory authority. Senator Moore led a group of 13 Massachusetts legislators last year urging Congress to reject language in the so-called ‘One Big Beautiful Bill’ that would place a 10-year moratorium on state-level artificial intelligence regulation. NCSL also early this year urged Congress to address betting markets like Polymarket and Kalshi that operate under ‘event contract’ rules, evading state-level laws by misrepresenting business practices. While the AI regulation moratorium was stripped from the OBBB and failed in a subsequent bill, President Donald Trump signed an Executive Order implementing it on a shaky legal footing, while Congress has still yet to address the betting market issue.
The letter is signed by Marcus C. Evans Jr., President of NCSL and a Democratic Representative in the Illinois House, as well as Barry Usher, NCSL President-Elect and a Republican Senator in the Montana Senate.
Full text of the letter can be viewed online here.
###
