The Gramm-Leach-Bliley Act (GLBA or Act) requires "financial institutions" (which includes colleges and universities) to protect the privacy of their customers, including customers' nonpublic, personal information. Because universities are governed by GLBA, Western Michigan University has a responsibility to secure the personal records of its students and employees. To ensure this protection, GLBA mandates all institutions establish appropriate administrative, technical, and physical safeguards.
By customer information, the Gramm Leach Bliley Act means information typically gathered in connection with obtaining a financial product or service; this includes but is not limited to include names, addresses, phone numbers, bank and credit card account numbers, income and credit histories, and Social Security numbers.
In an effort to set safeguarding standards, the Act directs that all financial institutions implement an Information Security Program, and designate a program coordinator.
The Information Security Program must include five main elements:
Last Revised: December 2012 | WMU is grateful for the support of Purdue University in the development of its GLB policy. All adapted work is used with permission.