Updating America’s Financial Privacy Framework for the 21st Century

Digital Assets and Bank RegulationHouse Financial Services · 2026-03-17 · 119th Congress
The House Financial Services Committee held this hearing to examine the Gramm-Leach-Bliley Act (GLBA), the 26-year-old federal financial privacy law, and a Republican discussion draft that would add consumer access, deletion, and data-minimization rights while preempting state privacy laws. Begins at 0:30:22
Transcript
Highlights

Title

Modernizing the Gramm-Leach-Bliley Act's financial data privacy rules

Purpose

The House Financial Services Committee held this hearing to examine the Gramm-Leach-Bliley Act (GLBA), the 26-year-old federal financial privacy law, and a Republican discussion draft that would add consumer access, deletion, and data-minimization rights while preempting state privacy laws. Witnesses from the banking, fintech, business, and consumer-advocacy sectors testified on federal preemption, private rights of action, screen scraping versus APIs, and the CFPB's role in enforcement, while Democrats also pressed witnesses on DOJ/DOGE access to sensitive government data and the CFPB's reduced capacity. Begins at0:30:22

Who spoke

Chairman French Hill (R-AR)0:30:22: Opened the hearing on updating GLBA, stressing the value of its technology-neutral framework0:30:44 and urging a "scalpel, not a sledgehammer" approach to reform0:33:06; later questioned witnesses on technological neutrality1:05:51 and screen scraping1:10:05.

Ranking Member Maxine Waters (D-CA)0:33:57: Argued Americans have no control over how their data is used and accused the Trump administration of handing sensitive data to DHS to target immigrants0:34:42 and of undermining the CFPB0:35:39; later pressed on DOJ/Musk access to Treasury and CFPB systems1:11:12.

Rep. Andy Barr (R-KY), Financial Institutions Subcommittee Chair0:38:21: Called for a national GLBA framework and warned against private rights of action padding "the pockets of the trial bar"0:39:07; later argued preemption would cut compliance costs and improve consumer choice1:59:01.

Rep. Bill Foster (D-IL), Financial Institutions Subcommittee Ranking Member0:39:32: Noted the CFPB's open banking and data broker oversight work under Dodd-Frank0:39:56; later discussed his bipartisan Stop ID Fraud Act and asked about API/agentic-commerce standards1:43:05.

Nathan Taylor, Morrison Foerster0:40:51: Said GLBA's notice-and-opt-out framework remains meaningful and proposed adding access, deletion, and full federal preemption0:44:25; confirmed data aggregators are covered "financial institutions" under GLBA1:17:56.

Clara Kim, Bank Policy Institute0:45:55: Argued for a single, fully preemptive national GLBA standard0:48:07 and said dual state/federal compliance regimes raise costs that trickle down to consumers1:09:45; supported a general ban on screen scraping1:25:54.

Steve Boms, Financial Data and Technology Association (FDATA)0:50:54: Testified GLBA already covers open banking platforms via the significantly-engaged test, Finders Rule, and service-provider provisions0:52:10; said screen scraping remains a "critical fallback" for millions and opposed a ban1:16:51.

Jordan Crenshaw, U.S. Chamber of Commerce0:55:36: Cited an ITIF estimate that state privacy fragmentation could cost the economy $1 trillion over 10 years0:56:46; said 71% of financial-services small businesses worry about complying with a state patchwork0:57:07; opposed private rights of action, citing the CAIPA/Adidas litigation as an example of forum shopping1:19:33.

Laura MacCleery, UnidosUS1:00:39: Warned the discussion draft's preemption would block stronger state protections like California's opt-in consent1:01:56; detailed IRS data-sharing errors with DHS, citing a court finding of 42,695 legal violations1:03:11; argued data privacy is "democratic infrastructure" tied to First and Fourth Amendment rights1:05:21.

Rep. Bill Huizenga (R-MI), Vice Chairman1:16:19: Polled witnesses on whether GLBA needs clarification on screen scraping1:16:21 and questioned Crenshaw on private-right-of-action costs1:18:24.

Rep. Brad Sherman (D-CA)1:21:32: Cited $19.7 billion returned to consumers and $5 billion in CFPB civil penalties1:22:02; argued preemption is acceptable only with high, not weak, national standards1:22:57.

Rep. Frank Lucas (R-OK)1:26:23: Asked about the status quo need for GLBA updates and codification versus "regulatory whiplash" from shifting agency rules1:27:08.

Rep. David Scott (D-GA)1:31:20: Questioned Boms on written information security programs (WISPs) and root causes of SEC data-security findings1:32:351:36:07.

Rep. Pete Sessions (R-TX)1:36:37: Asked Crenshaw to detail Texas's consensus privacy law as a model, including its rejection of private rights of action1:37:59.

Rep. Sylvester Turner/Wagner (R-MO)1:47:46: Asked Crenshaw about the compliance/competitiveness costs of the state patchwork, citing a possible $50 billion GDP hit and 700,000 jobs from Colorado's AI law1:50:14.

Rep. Emanuel Cleaver (D-MO)1:53:14: Asked MacCleery about AI safeguards for underserved communities and UnidosUS's "voice, values, investment" governance framework1:54:04.

Rep. Troy Downing/Daines (R-MT)2:39:57: Asked about technology-neutral drafting, CFPB's rulemaking role, and state versus federal roles in privacy enforcement2:40:21.

Rep. Juan Vargas (D-CA)2:35:12: Pressed Boms and Kim on whether an open-banking rule with clear API protocols would eliminate the need for screen scraping2:35:52; criticized preemption without a private right of action2:39:22.

Rep. Warren Davidson (R-OH)2:20:38: Warned against AI "blanket immunity" to harvest data and asked about opt-in vs. opt-out and data disaggregation risks2:22:392:24:05.

Rep. Sean Casten (D-IL)2:15:03: Raised concerns about AI companies avoiding liability for data misuse and CISA's uploading of sensitive information into ChatGPT2:16:27; asked whether AI tools can be "ring-fenced" to prevent data leakage2:17:24.

Rep. Ayanna Pressley (D-MA)2:25:32: Used a hypothetical renter, "Mark," to argue for open banking and consumer control over shared financial data2:26:00; asked MacCleery about language-accessibility in financial disclosures2:29:39.

Rep. Ro Khanna/Luardo (D-CA)2:34:42: Cited a 2021 NORC survey finding 93% of fintech users unaware their data is being scraped2:35:12; pushed for a federal requirement that all institutions build secure APIs2:37:35.

Rep. Rashida Tlaib (D-MI)2:44:42: Highlighted CFPB's closure of disparate-impact fair-lending investigations2:45:40 and cited Kroger's reported $527 million profit from selling shopping data in 20242:48:15.

Rep. Bryan Steil (R-WI)2:50:06: Asked Taylor whether GLBA's definition of "financial institution" is sufficiently clear for data aggregators2:51:48, and asked Crenshaw to rank state privacy laws by workability2:53:44.

Rep. Erin Houchin/Stutzman (R-IN)2:55:32: Compared Indiana's and California's differing treatment of GLBA-covered entities and polled the full panel on support for a uniform national standard2:58:01.

Key moments

MacCleery testified a federal judge found the IRS shared taxpayer data with DHS in a manner that violated the law at least 42,695 times, after DHS's request escalated from 700,000 to 7 million to 1.28 million records before 47,000 were ultimately sent1:03:11.

MacCleery cited a sworn affidavit from CFPB's former chief technologist stating no employee had ever had blanket data access before, but DOJ staff were granted "god tier" access the day they arrived1:15:32.

Crenshaw cited a 2022 ITIF report estimating a fragmented state privacy landscape could cost the U.S. economy $1 trillion over 10 years, $200 billion of it falling on small businesses, and Chamber survey data showing 71% of small financial-services firms worry about patchwork compliance costs0:56:460:57:07.

Crenshaw and Sessions discussed a California Invasion of Privacy Act lawsuit against Adidas allowed to proceed in the Southern District of California while a similar case was rejected in the Northern District, illustrating inconsistent private-right-of-action outcomes1:19:331:20:00.

Kim, Crenshaw, and Taylor all endorsed full federal preemption of state privacy laws, while MacCleery and Waters argued this would block stronger state protections (e.g., California's opt-in consent, Colorado, Connecticut, Virginia) without raising the federal floor1:01:561:59:55.

Boms said 93%–like figures aside, member institutions of FDATA are all subject to GLBA through the "significantly engaged" test, the 2021 Finders Rule, and service-provider contract provisions, and that the oldest FDATA member company is as old as GLBA itself, founded in 19990:52:241:35:07.

MacCleery said S&P Global estimates depositors miss $40 billion annually in savings interest due to switching friction that an open banking (rule 1033) framework would reduce1:46:47.

Tlaib cited a 2024 report that Kroger made an estimated $527 million in profit — about one-third of its net income — from selling shopping data, tying this to concerns about surveillance pricing2:48:15.

On screen scraping, witnesses split: Kim and Crenshaw favored a ban (though Crenshaw questioned whether GLBA is the right vehicle)1:16:51, while Boms said it remains a necessary fallback for smaller institutions lacking API resources0:50:542:36:17.

Casten and MacCleery raised concerns that AI tools (e.g., ChatGPT) have absorbed sensitive government data uploaded by officials, with MacCleery noting it's difficult to know whether compromised data can ever be fully secured again2:15:032:19:21.

Metadata

CommitteeHouse Financial Services
Chamber / CongressHouse · 119th Congress
Date2026-03-17
TypeHearing
Witnesses
Ms. Clara Kim — Senior Vice President, Bank Policy Institute
Mr. Jordan Crenshaw — Senior Vice President, Technology Engagement Center, U.S. Chamber of Commerce
Ms. Laura MacCleery — Senior Director, Policy and Advocacy, UnidosUS
Mr. Nathan Taylor — Partner, Morrison Foster
Mr. Steve Boms — Executive Director, Financial Data and Technology Association
Videoyoutube
Transcript371 caption blocks · 25,013 words · 3:00:51 runtime
EventCongress.gov 119049