Article

Financial Services Data Privacy Compliance Checklist for 2026

On July 16, 2026, New York's Department of Financial Services announced a $50 million penalty against Swedbank for withholding information from investigators and failing to fully cooperate with regulatory information requests — a stark reminder that compliance failures now carry eye-watering price tags even when they involve information governance, not just a breach itself (NY DFS). Three months earlier, Massachusetts securities regulator William Galvin fined Fidelity Brokerage Services $1.25 million after a breach exposed roughly 77,000 customers' data and Fidelity failed to notify many affected residents, including customers' relatives and minor children (DataBreaches.net). Compliance in financial services is no longer a once-a-year audit exercise — 2025 closed out every remaining grace period on the two biggest frameworks in the industry, GLBA Safeguards Rule enforcement and NY DFS Part 500, and firms are now expected to have every control live, evidenced, and audit-ready.

This piece is a working checklist, not a theory of compliance. Every item below traces back to a specific regulatory requirement — GLBA's Safeguards Rule, PCI DSS 4.0.1, NY DFS Part 500, and the state privacy-law layer that increasingly touches financial data even where GLBA carves out an exemption.

GLBA Safeguards Rule: the nine elements the FTC requires

The FTC's Safeguards Rule requires covered financial institutions to maintain a written information security program with administrative, technical, and physical safeguards, and Section 314.4 spells out nine specific elements every program must include (FTC):

  1. Designate a Qualified Individual to implement and supervise the program — no specific degree or title required, but the responsibility ultimately sits with the company even if it's outsourced.

  2. Conduct and document a written risk assessment, with periodic reassessment as operations or threats change.

  3. Design and implement safeguards, including access controls, encryption of customer information at rest and in transit, multi-factor authentication, and secure disposal of customer data no later than two years after last use.

  4. Regularly monitor and test safeguards — continuous monitoring, or annual penetration testing plus vulnerability scans every six months if not.

  5. Train staff on security awareness, with specialized training for anyone with hands-on program responsibilities.

  6. Monitor service providers contractually, requiring them to maintain safeguards and permit periodic reassessment.

  7. Keep the program current as operations, risks, and threats evolve.

  8. Maintain a written incident response plan covering roles, communications, remediation, and post-incident review.

  9. Require the Qualified Individual to report in writing to the Board (or a senior officer) at least annually on compliance status, risks, and test results.

The Rule's 2023 amendment layered on a federal breach-reporting requirement: any notification event involving unauthorized acquisition of 500 or more consumers' unencrypted information must be reported to the FTC within 30 days of discovery (Accountable; FTC).

PCI DSS 4.0.1: no more transition period

PCI DSS 4.0.1 became the current version of the standard on January 1, 2025, and every "future-dated" requirement introduced with 4.0 — treated as best practice for a year — became fully mandatory on March 31, 2025 (Silver Lining Convergence; Fortra). There is no remaining grace period: any organization storing, processing, or transmitting cardholder data is expected to already have these controls in place. Non-compliance can trigger fines ranging from $5,000 to $100,000 per month from acquiring banks, plus loss of card-processing privileges (HYPR). Requirement 6.5.4 is unambiguous that production cardholder data — including primary account numbers — must not be used in test or development environments, full stop, with no carve-out for "trusted" internal environments.

NY DFS Part 500: the last phase is over

New York's Department of Financial Services closed out the final phase of its Second Amendment to 23 NYCRR Part 500 on November 1, 2025, when expanded multi-factor authentication (Section 500.12) and complete asset inventory requirements (Section 500.13) became fully enforceable (FCI Cyber; Beyond Identity). MFA must now cover any individual accessing any information system — employees, contractors, and vendors, on-premises or in the cloud — with the only alternative being a CISO-approved, annually reviewed compensating control (Crowell & Moring). Asset inventories must be living records tracking ownership, location, classification, and disposal status for every information system — DFS has explicitly said a static spreadsheet will not satisfy an examination (Centraleyes).

DFS enforcement has moved from occasional to routine. It fined PayPal $2 million in January 2025 for cybersecurity failures tied to unauthorized exposure of customer data (Hunton Andrews Kurth), settled with Healthplex for $2 million in August 2025 over inadequate cybersecurity measures following a 2021 breach, and reached a $2.25 million settlement with Delta Dental in April 2026 over its response to a MOVEit-linked breach (Hunton Andrews Kurth). Statutory penalties under New York Banking Law can run $2,500 per day per violation for straightforward noncompliance, escalating toward $250,000 per day for more serious, ongoing failures (Centraleyes; HYPR). The annual Certification of Material Compliance — or Acknowledgment of Noncompliance — for the 2025 calendar year is due April 15, 2026, and it now has to attest that universal MFA and a complete asset inventory were both operating for the full year (HYPR).

Where state privacy laws intersect — and where they don't

GLBA-regulated data enjoys a broad exemption from the CCPA/CPRA: personal information collected, processed, sold, or disclosed under GLBA or the California Financial Information Privacy Act is generally excluded from CCPA obligations (Mortgage Bankers Association comment letter to the CPPA). But that exemption is entity- and data-type specific, not blanket — a financial institution's non-GLBA data (marketing data, employee data, data from lines of business not "financial in nature") can still fall under CCPA/CPRA, and the CPPA has continued to push back on financial-industry attempts to broaden the carve-out during its 2025 rulemaking on automated decision-making rules. Firms operating across state lines also can't assume federal preemption solves everything: NY DFS Part 500 layers state-specific cybersecurity obligations directly on top of GLBA for any entity DFS licenses, regardless of federal exemption status.

A practical financial services data privacy compliance checklist

Use this as the working framework — each item maps to a specific requirement above.

  1. Written information security program (GLBA §314.4(a)). Confirm you have a designated Qualified Individual, and that the program is written, current, and scoped to your actual size, complexity, and data sensitivity (FTC).

  2. Documented risk assessment (GLBA §314.4(b)). Verify your risk assessment is written, includes defined evaluation criteria, and has been refreshed since your last material operational change.

  3. Encryption and MFA everywhere required (GLBA §314.4(c); NY DFS §500.12). Confirm customer information is encrypted at rest and in transit, and that MFA covers every individual accessing every information system — not just remote or privileged users — per the November 2025 DFS deadline (FCI Cyber).

  4. No production cardholder data in test/dev (PCI DSS 4.0.1, Req. 6.5.4). Confirm test and development environments never contain live primary account numbers, with no exception for internal or "trusted" environments.

  5. Complete, living asset inventory (NY DFS §500.13). Confirm your asset inventory tracks owner, location, classification, and disposal status for every information system, and isn't a static, periodically-updated spreadsheet (Centraleyes).

  6. Breach and incident notification readiness (GLBA amendment; NY DFS §500.17). Confirm you can identify a 500-consumer notification event and report to the FTC within 30 days, and separately meet DFS's 72-hour cybersecurity incident notice requirement.

  7. Annual reporting to the board and to regulators (GLBA §314.4(i); NY DFS §500.17). Confirm your Qualified Individual reports to the board at least annually, and that your DFS Certification of Material Compliance (or Acknowledgment of Noncompliance) is ready for the April 15 filing deadline.

  8. Service provider oversight (GLBA §314.4(f)). Confirm contracts with vendors and service providers spell out security expectations and include a right to monitor and periodically reassess them.

A quick checklist

  • Does your MFA coverage extend to every individual, contractor, and vendor touching any information system — not just remote or privileged accounts?

  • Is your asset inventory a living, queryable record, or something you'd have to rebuild by hand if DFS asked for it tomorrow?

  • Could you identify, within 30 days, whether a given incident meets the 500-consumer GLBA notification threshold?

  • Does any test, QA, or vendor-facing environment still contain real cardholder data or unmasked customer information?

  • If a regulator asked which of your data falls under a GLBA exemption versus CCPA/CPRA obligations, could you answer with confidence today?

The bottom line

The regulatory bar for financial services data privacy didn't just get more detailed in 2025-2026 — it stopped offering room to phase in. GLBA's Safeguards Rule, PCI DSS 4.0.1, and NY DFS Part 500 are all fully in force, and enforcement actions from PayPal to Delta Dental to Fidelity Brokerage show regulators are actively testing whether the controls exist, not just whether the paperwork says they should.

C² Data Privacy Platform discovers sensitive data across core banking systems, databases, and vendor-facing environments, and masks or de-identifies it automatically before delivery — so financial firms can prove data is protected everywhere it lives, not just in production. Book a demo to see it run against your own schema.

Sources: NY DFS — Swedbank $50 million penalty announcement, DataBreaches.net — Fidelity Brokerage Services $1.25M fine, FTC — Safeguards Rule: What Your Business Needs to Know, Accountable — GLBA Safeguards Rule updates guide, Silver Lining Convergence — PCI DSS v4.0.1 changes in 2025, Fortra — PCI DSS 4.0 vs 4.0.1 compliance deadline, HYPR — PCI DSS 4.0.1 key changes, FCI Cyber — NYDFS 23 NYCRR 500 guide, Beyond Identity — NYDFS Part 500 2025 deadlines, Crowell & Moring — NYDFS cybersecurity enforcement alert, Centraleyes — NYDFS Cybersecurity Regulation dates and facts, Hunton Andrews Kurth — NY privacy and cybersecurity law blog, New York tag, HYPR — Cost of NYDFS Cybersecurity Noncompliance 2026, HYPR — Cybersecurity Regulations for Financial Services 2026, Mortgage Bankers Association — comment letter to CPPA on GLBA/CCPA exemption, C² Data Technology.