GLBA reuse and redisclosure: can vendors use bank customer data?

Under GLBA privacy rules, a vendor that receives nonpublic personal information from a bank under an exception can generally use and disclose it only to carry out that exception's activity. Licensing it for AI training is usually outside that scope, so vendors should limit licenses to their own records.

Can a vendor reuse customer data it received from a bank?

Usually not beyond the purpose it received the data for. Under the Gramm-Leach-Bliley Act privacy rules, a vendor or processor that receives nonpublic personal information from a financial institution under an exception generally may use and disclose it only to carry out the activity that exception covers. Licensing that information to an AI developer is a different use, so it normally needs a separate path or an exclusion.

The FTC's GLBA business guidance describes the Privacy Rule, with its customer notices and opt-out rights before sharing with certain nonaffiliated third parties, and the Safeguards Rule, which requires a written information security program. This is general information, not legal, tax or financial advice. Confirm with your own counsel, who should read the rule text that applies to your institution type.

What are the reuse and redisclosure limits?

The privacy rule of the Consumer Financial Protection Bureau, known as Regulation P and codified at 12 CFR Part 1016, contains a section on limits on redisclosure and reuse of nonpublic personal information. The agencies' versions for other institution types follow the same structure. Read the exact section for your regulator; the points below summarize the idea, not the text.

  • Information received under an exception, such as processing a transaction the customer requested, can generally be used and disclosed only within that exception's purpose.
  • Information received outside an exception, for example after the customer was given notice and a chance to opt out, can generally be disclosed only to the institution's affiliates, to the recipient's own affiliates (who face the same limits), or to anyone the institution itself could lawfully have disclosed it to.
  • In both cases the original notice and any opt-out choices matter, which is why the recipient cannot treat a copy as its own asset.

For a vendor, the sentence to remember is simple: the contract and the exception define the permitted use, and a data license is rarely inside either.

Which vendors and BPOs run into this?

Vendor typeWhat it typically receivesWhy reuse is a red flag
Loan servicing BPO or call centerAccount details, payment history, call recordingsReceived to service the bank's accounts, not to train others' models
Collections agencyDebtor identity, balances, contact attemptsReceived to collect on the bank's behalf
Core-processing or fintech platform providerTransaction records, onboarding dataReceived to run the bank's product
Document-processing vendorApplications, statements, IDsReceived to extract data for the bank
Marketing or analytics vendorCustomer lists and segmentsUse limited to the bank's campaign instructions

Where data belongs to the bank's customers, the vendor does not hold the rights to license it. The question of whether business customers are covered at all is addressed in the page on whether GLBA covers business customers' data.

What can a financial-services vendor still license?

Rights depend on who created the record, not on which system stores it. Many vendors hold material that is plainly their own.

Record typeLikely rights positionNext check
The vendor's internal SOPs, runbooks and training materialVendor's own workConfirm no customer data embedded in examples
Engineering tickets, code reviews and release notesVendor's own workScan for customer identifiers and secrets
Internal chat about process design and escalationVendor's own work, with employee-privacy checksRemove customer account details
HR and finance operations of the vendorVendor's own recordsExclude personnel files
Customer account records, calls and statements received from a bankProbably restricted by the exception and the contractExclude unless the institution agrees in writing

The privacy side of free text is covered in the page on emails and Slack messages as sensitive personal information, and the de-identification standard for California is in the guide to the three commitments for de-identified data.

A screen partners can use

Use these five questions before you introduce a fintech service provider or BPO. They are not legal advice; they help you decide whether to proceed.

  1. Is most of the company's data about its own operations, or about a bank's or lender's customers?
  2. Does the company hold a written agreement with each institution that allows any reuse?
  3. Can the company separate its own records from the institution-supplied records in each system?
  4. Does someone at the company own privacy and vendor contracts, and can they join a call?
  5. Would the sponsor consider an exclusive license limited to the company's own records?

If question one comes back mostly institution data and question two has no written permission, treat it as a red flag and park the introduction. The company fit checker gives a preliminary, non-binding screen without contact details.

How rights review handles this

The company completes a data inventory listing systems and what can be exported. SourceX qualifies the company on size, history, data breadth and rights, and agrees redaction and exclusion requirements with the company before any work begins. Data is delivered only after an executed agreement and the company's authorization. Partners never export, upload or describe confidential records. The related page on student records held by education vendors shows the same pattern in another sector.

What to say to a sponsor

Questions for the company's counsel

  • Under which exception did we receive institution data, and what does each contract say about reuse?
  • Which systems mix our own records with institution-supplied records?
  • Can we separate them by client, product line or time period?
  • Do any institutions have audit or approval rights over derivative uses?
  • Would an institution consent in writing to a limited, de-identified release, and who would ask?

Companies sometimes find that one or two institutions hold most of the sensitive material. Excluding those clients can leave a clean, valuable dataset of the vendor's own internal work, which is often what buyers wanted in the first place.

What a partner should not do

  • Do not ask the company to describe or send account records or call recordings.
  • Do not suggest that the vendor may use bank-supplied data because it holds a copy.
  • Do not give a view on whether an exception applies; that belongs to counsel.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; no reward is guaranteed.

Next step

Read how the process works. If you know a US company with 50+ full-time employees at peak (contractors excluded) whose valuable records are its own, register as a partner and make the introduction.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does the reuse limit apply if the data is de-identified?

Different rules can apply to information that has been properly de-identified, but the standard is demanding and depends on the rule that applies. A vendor should not assume that removing names is enough. Counsel should confirm the method, and the institution's contract may impose stricter limits than the law.

What if the bank's contract does not mention reuse at all?

Silence is not permission. A vendor that received data to perform a service is generally limited to that service, and contracts usually add confidentiality and security terms. Before any license, the vendor's counsel should read the agreement and ask the institution for written consent if reuse is wanted.

Can a fintech license its own product usage data?

Often more easily than institution-supplied records, because it concerns the company's own platform activity. Even so, counsel should check whether the usage data contains customer financial information and what notices and contracts say. The company decides what to include with SourceX during rights review.

Do these limits apply to a company that is not a bank?

The privacy rules cover a range of financial institutions, including many non-bank businesses, and which agency's rule applies depends on the type of company. A business that receives information from such an institution may face the reuse limits through its role. Counsel should confirm.

Can a referral partner help a vendor decide what is licensable?

No. A partner makes the introduction and shares basic fit information. Deciding what the vendor may license is for its counsel and the company's decision-makers, working with SourceX during rights review, and nothing is binding until the company signs.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment