In 1999, Congress enacted the Gramm-Leach-Bliley Act (GLBA), which contains rules regarding the privacy of NPI collected by financial institutions. The GLBA defines NPI as:
“Personally identifiable financial information – provided by a consumer to a financial institution, resulting from any transaction with the consumer or any service performed for the consumer; or otherwise obtained by the financial institution.”
The term does not include publicly available information lawfully made available by federal, state, and local governments.
With so much sensitive data shared throughout mortgage processing workflows, it’s no surprise that regulations exist to protect NPI and that compliance with data privacy regulations is a top concern for lending institutions.
Two rules within the GLBA deal with the safeguarding and privacy of NPI.
Beyond the GLBA, mortgage companies and other financial institutions must also comply with regulations from the Consumer Financial Protection Bureau (CFPB) and state privacy laws such as those in California, Vermont, New York, and Arizona.
While compliance is a top concern for mortgage companies and financial institutions, consumers have data privacy concerns of their own as it relates to obtaining a mortgage: ease of use. Traditional solutions (such as secure portals) frustrate end users with separate, redundant applications and workflows, new accounts, and passwords to manage.
A more modern approach to collecting and sharing documents containing NPI could be as straightforward as a simple email exchange of attachments with additional layers of security for advanced privacy protection. With this approach, you can protect NPI everywhere it’s shared throughout the mortgage transaction process to meet the GLBA’s Safeguards Rule requirements for secure storage and transmission of sensitive customer data. Plus, you can enable more efficient client communications with streamlined service models that help differentiate your business from competitors, build client trust, and ultimately drive business growth.
As mortgage workflows increasingly go digital, institutions need sophisticated yet user-friendly tools to protect NPI throughout the loan lifecycle. Virtru provides a comprehensive security suite that ensures NPI protection from initial application through closing, while keeping processes smooth for both staff and clients.
Protect sensitive NPI in Gmail, Google Drive, Outlook, and file sharing workflows with end-to-end encryption. Set expiration dates, revoke access, and prevent forwarding of mortgage documents. Watermark sensitive files and maintain control throughout the entire loan process.
Deploy rules-based encryption that automatically detects and protects NPI across your mortgage workflows. Configure custom policies to secure sensitive data like social security numbers, bank statements, and tax documents - ensuring GLBA compliance without slowing down loan processing.
Monitor who accesses protected NPI throughout the mortgage lifecycle with detailed audit logs. Track when borrower information is accessed and by whom, simplifying both GLBA compliance and loan audits.
Take full control of your encryption with Virtru Private Keystore, preventing unauthorized access to NPI even from cloud providers.
To learn more about how Virtru can help secure NPI while maintaining compliance and streamlining mortgage workflows, reach out to our team today.
The editorial team consists of Virtru brand experts, content editors, and vetted field authorities. We ensure quality, accuracy, and integrity through robust editorial oversight, review, and optimization of content from trusted sources, including use of generative AI tools.
View more posts by Editorial TeamSee Virtru In Action
Sign Up for the Virtru Newsletter
Contact us to learn more about our partnership opportunities.