GLBA reuse and redisclosure: can vendors use bank customer data?
Under GLBA privacy rules, a vendor that receives nonpublic personal information from a bank under an exception can generally use and disclose it only to carry out that exception's activity. Licensing it for AI training is usually outside that scope, so vendors should limit licenses to their own records.
Can a vendor reuse customer data it received from a bank?
Usually not beyond the purpose it received the data for. Under the Gramm-Leach-Bliley Act privacy rules, a vendor or processor that receives nonpublic personal information from a financial institution under an exception generally may use and disclose it only to carry out the activity that exception covers. Licensing that information to an AI developer is a different use, so it normally needs a separate path or an exclusion.
The FTC's GLBA business guidance describes the Privacy Rule, with its customer notices and opt-out rights before sharing with certain nonaffiliated third parties, and the Safeguards Rule, which requires a written information security program. This is general information, not legal, tax or financial advice. Confirm with your own counsel, who should read the rule text that applies to your institution type.
What are the reuse and redisclosure limits?
The privacy rule of the Consumer Financial Protection Bureau, known as Regulation P and codified at 12 CFR Part 1016, contains a section on limits on redisclosure and reuse of nonpublic personal information. The agencies' versions for other institution types follow the same structure. Read the exact section for your regulator; the points below summarize the idea, not the text.
- Information received under an exception, such as processing a transaction the customer requested, can generally be used and disclosed only within that exception's purpose.
- Information received outside an exception, for example after the customer was given notice and a chance to opt out, can generally be disclosed only to the institution's affiliates, to the recipient's own affiliates (who face the same limits), or to anyone the institution itself could lawfully have disclosed it to.
- In both cases the original notice and any opt-out choices matter, which is why the recipient cannot treat a copy as its own asset.
For a vendor, the sentence to remember is simple: the contract and the exception define the permitted use, and a data license is rarely inside either.
Which vendors and BPOs run into this?
| Vendor type | What it typically receives | Why reuse is a red flag |
|---|---|---|
| Loan servicing BPO or call center | Account details, payment history, call recordings | Received to service the bank's accounts, not to train others' models |
| Collections agency | Debtor identity, balances, contact attempts | Received to collect on the bank's behalf |
| Core-processing or fintech platform provider | Transaction records, onboarding data | Received to run the bank's product |
| Document-processing vendor | Applications, statements, IDs | Received to extract data for the bank |
| Marketing or analytics vendor | Customer lists and segments | Use limited to the bank's campaign instructions |
Where data belongs to the bank's customers, the vendor does not hold the rights to license it. The question of whether business customers are covered at all is addressed in the page on whether GLBA covers business customers' data.
What can a financial-services vendor still license?
Rights depend on who created the record, not on which system stores it. Many vendors hold material that is plainly their own.
| Record type | Likely rights position | Next check |
|---|---|---|
| The vendor's internal SOPs, runbooks and training material | Vendor's own work | Confirm no customer data embedded in examples |
| Engineering tickets, code reviews and release notes | Vendor's own work | Scan for customer identifiers and secrets |
| Internal chat about process design and escalation | Vendor's own work, with employee-privacy checks | Remove customer account details |
| HR and finance operations of the vendor | Vendor's own records | Exclude personnel files |
| Customer account records, calls and statements received from a bank | Probably restricted by the exception and the contract | Exclude unless the institution agrees in writing |
The privacy side of free text is covered in the page on emails and Slack messages as sensitive personal information, and the de-identification standard for California is in the guide to the three commitments for de-identified data.
A screen partners can use
Use these five questions before you introduce a fintech service provider or BPO. They are not legal advice; they help you decide whether to proceed.
- Is most of the company's data about its own operations, or about a bank's or lender's customers?
- Does the company hold a written agreement with each institution that allows any reuse?
- Can the company separate its own records from the institution-supplied records in each system?
- Does someone at the company own privacy and vendor contracts, and can they join a call?
- Would the sponsor consider an exclusive license limited to the company's own records?
If question one comes back mostly institution data and question two has no written permission, treat it as a red flag and park the introduction. The company fit checker gives a preliminary, non-binding screen without contact details.
How rights review handles this
The company completes a data inventory listing systems and what can be exported. SourceX qualifies the company on size, history, data breadth and rights, and agrees redaction and exclusion requirements with the company before any work begins. Data is delivered only after an executed agreement and the company's authorization. Partners never export, upload or describe confidential records. The related page on student records held by education vendors shows the same pattern in another sector.
What to say to a sponsor
Questions for the company's counsel
- Under which exception did we receive institution data, and what does each contract say about reuse?
- Which systems mix our own records with institution-supplied records?
- Can we separate them by client, product line or time period?
- Do any institutions have audit or approval rights over derivative uses?
- Would an institution consent in writing to a limited, de-identified release, and who would ask?
Companies sometimes find that one or two institutions hold most of the sensitive material. Excluding those clients can leave a clean, valuable dataset of the vendor's own internal work, which is often what buyers wanted in the first place.
What a partner should not do
- Do not ask the company to describe or send account records or call recordings.
- Do not suggest that the vendor may use bank-supplied data because it holds a copy.
- Do not give a view on whether an exception applies; that belongs to counsel.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; no reward is guaranteed.
Next step
Read how the process works. If you know a US company with 50+ full-time employees at peak (contractors excluded) whose valuable records are its own, register as a partner and make the introduction.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does the reuse limit apply if the data is de-identified?
Different rules can apply to information that has been properly de-identified, but the standard is demanding and depends on the rule that applies. A vendor should not assume that removing names is enough. Counsel should confirm the method, and the institution's contract may impose stricter limits than the law.
What if the bank's contract does not mention reuse at all?
Silence is not permission. A vendor that received data to perform a service is generally limited to that service, and contracts usually add confidentiality and security terms. Before any license, the vendor's counsel should read the agreement and ask the institution for written consent if reuse is wanted.
Can a fintech license its own product usage data?
Often more easily than institution-supplied records, because it concerns the company's own platform activity. Even so, counsel should check whether the usage data contains customer financial information and what notices and contracts say. The company decides what to include with SourceX during rights review.
Do these limits apply to a company that is not a bank?
The privacy rules cover a range of financial institutions, including many non-bank businesses, and which agency's rule applies depends on the type of company. A business that receives information from such an institution may face the reuse limits through its role. Counsel should confirm.
Can a referral partner help a vendor decide what is licensable?
No. A partner makes the introduction and shares basic fit information. Deciding what the vendor may license is for its counsel and the company's decision-makers, working with SourceX during rights review, and nothing is binding until the company signs.
Related pages
- Does GLBA cover business customers' data, and what can a lender license?
- Are emails and Slack messages sensitive personal information under the CPRA?
- CCPA deidentified data: the three commitments a company must make
- Check Company Fit for Data Licensing
- FERPA and EdTech vendors: which student records are excluded from a data license?
- How SourceX US company data referrals work
Free resources
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment