Gramm-Leach-Bliley Act Disposal Rules for Insurance Agencies

GLBA disposal rules insurance agencies - New York Shredding

Insurance agencies across New York handle volumes of sensitive customer information every day — applications, policy documents, claims files, medical histories, and financial records. Under the Gramm-Leach-Bliley Act (GLBA), financial institutions — including many insurance companies and agencies — are required to protect this information throughout its lifecycle, including at the point of disposal. GLBA disposal rules for insurance agencies establish clear standards for how “customer information” must be destroyed when it is no longer needed, and failure to comply can result in regulatory action, civil penalties, and reputational damage.

For insurance professionals in New York City, Long Island, Westchester County, and the Hudson Valley, understanding how GLBA applies to your agency’s paper records is an important part of running a compliant operation. While GLBA is often discussed in the context of banks and lenders, its Safeguards Rule and related disposal requirements apply broadly to entities that are “significantly engaged” in financial activities — a definition that clearly captures insurance agencies and brokerages. This guide breaks down what GLBA requires of insurance agencies when it comes to disposing of paper customer records.

How GLBA Applies to Insurance Agencies

The Gramm-Leach-Bliley Act was enacted in 1999 and is administered by the Federal Trade Commission (FTC) for non-bank financial institutions, including most insurance agencies. The FTC’s updated Safeguards Rule, which took effect in 2023, significantly expanded and strengthened the data protection requirements for covered financial institutions. Under GLBA, insurance agencies that collect “nonpublic personal information” (NPI) about individual customers are subject to a range of data security obligations, including requirements around how that information must be destroyed.

Under the updated Safeguards Rule, covered insurance agencies must develop, implement, and maintain a comprehensive information security program that includes:

  • Procedures for securely disposing of customer information, whether in paper or electronic form
  • Written policies addressing how long customer records are retained and when they must be destroyed
  • Oversight of third-party service providers that handle customer information — including shredding vendors
  • Annual testing or monitoring of information security controls, including disposal procedures

New York insurance agencies that are also subject to the NY DFS Insurance Regulation have additional state-level requirements that may go further than GLBA in some areas. Working with an attorney familiar with both federal and New York-specific insurance regulations is advisable when building your compliance program.

What Customer Information Must Be Protected Under GLBA?

GLBA defines “nonpublic personal information” to include any information an individual provides to obtain a financial product or service, any information resulting from a transaction, and any information an agency otherwise obtains about an individual in connection with providing a financial product or service. For insurance agencies, this encompasses an enormous range of paper records:

  • Insurance applications (including medical history and financial information)
  • Policy declarations and endorsements containing customer identifying information
  • Claims files, including medical records obtained during a claims investigation
  • Premium payment records and billing statements
  • Underwriting worksheets containing income, credit, or health information
  • Correspondence with clients about their coverage or claims
  • Agent notes and customer relationship management printouts

Any of these documents that your agency decides to destroy must be disposed of using a method that renders the information unreadable and unrecoverable. Simply placing them in the recycling bin — even after tearing them — does not meet GLBA’s standard for “proper disposal.” The certified shredding services provided by professional shredding companies meet this standard.

The GLBA Disposal Rule: What “Proper Disposal” Means

The FTC’s Disposal Rule, which complements the Safeguards Rule, requires that covered entities take reasonable measures to protect against unauthorized access to or use of customer information in connection with its disposal. The FTC has provided guidance on what “reasonable measures” means in practice:

  • For paper records: Shredding, burning, or pulverizing the records to make them unreadable and unrecoverable
  • Contracting with a qualified disposal vendor: Using a third-party shredding company that takes appropriate measures to destroy the information and contractually commits to doing so
  • Documentation of disposal: Maintaining records of when and how customer information was destroyed, including any Certificate of Destruction from your shredding vendor

Simply tearing documents in half, depositing them in a standard recycling bin, or dumping them in dumpsters does not constitute “proper disposal” under GLBA. The FTC has brought enforcement actions against companies that disposed of customer information in ways that made it accessible to dumpster divers or other unauthorized persons. For New York insurance agencies, the consequences of improper disposal extend beyond federal penalties to potential action by the New York State Department of Financial Services under Insurance Regulation 173 and the SHIELD Act.

Building a GLBA-Compliant Records Disposal Program

Creating a disposal program that satisfies GLBA requirements involves several concrete steps. Your compliance team should work through the following:

  1. Conduct a records inventory: Identify all categories of customer records your agency holds in paper form, where they are stored, and how long they must be retained under applicable law and agency policy.
  2. Establish retention schedules: Define how long each category of record must be kept before it can be destroyed. Consult with your attorney to ensure your retention schedule accounts for state insurance regulations and any other applicable requirements.
  3. Select a certified shredding vendor: Choose a vendor with NAID AAA Certification or comparable credentials, and obtain a service agreement that includes a commitment to proper destruction and provision of Certificates of Destruction.
  4. Implement locked console collection: Place locked shredding consoles at points where customer records are generated or handled — reception desks, claim processing areas, agent workstations.
  5. Document destruction events: Retain Certificates of Destruction as part of your information security records. These documents demonstrate compliance if your agency is audited or investigated.

A recurring shredding schedule — weekly, biweekly, or monthly depending on your volume — combined with periodic one-time purges for archived materials will keep your agency’s disposal program running smoothly. Learn more about how our shredding process works to understand how easy it is to get started.

Third-Party Vendor Oversight Under GLBA

The GLBA Safeguards Rule requires covered institutions to oversee their service providers to ensure that appropriate safeguards are in place. This applies to your shredding vendor. Your information security program should include a process for vetting and monitoring third-party vendors that handle customer information — including those that collect and destroy physical records.

At a minimum, your agency should:

  • Review the shredding vendor’s NAID certification or equivalent credentials
  • Include appropriate security requirements in your service contract
  • Obtain a Certificate of Destruction after each shredding event
  • Periodically review the vendor relationship as part of your annual information security assessment

A reputable local shredding company serving New York City and Long Island will be accustomed to providing all of this documentation and will understand what insurance agencies and other regulated financial institutions require. For pricing information on scheduled service or one-time purges, reach out for a custom quote.

Practical Steps to Bring Your Insurance Agency Into GLBA Disposal Compliance

Many insurance agencies in New York are already partially compliant with GLBA disposal requirements — they use a shredder in the office, they have some policies around document handling — but they lack the documentation and systematic approach that regulators expect. Closing the compliance gap typically involves formalizing what already exists, adding missing elements, and creating the paper trail that demonstrates your program is real and consistently implemented.

Start by conducting a records inventory: walk through every area of your office and identify where paper customer records are stored, generated, or processed. Reception desks, claim processing areas, agent workstations, storage rooms, and off-site archives all need to be included. For each location, determine whether a locked shredding console should be placed there, and what records are being generated that will eventually need to be destroyed.

Next, review your service contract with any existing shredding vendor to confirm it includes the appropriate security commitments required by the Safeguards Rule. If your current vendor cannot provide a written commitment to protect customer information and supply a Certificate of Destruction after each event, it may be time to upgrade your vendor relationship. New York agencies across the five boroughs, Long Island, and Westchester County can access our full range of shredding services designed for regulated financial entities.

Why New York Businesses Choose New York Shredding

For over a decade, New York Shredding Document Destruction, Inc. has helped businesses across New York City, Long Island, Westchester, and the Hudson Valley protect their sensitive information through certified, HIPAA-compliant shredding services. Our industrial-grade shredding equipment, locked on-site consoles, and Certificate of Destruction give your business the proof it needs for any compliance audit.

Whether you need scheduled shredding, a one-time purge, or hard drive destruction, we serve all five boroughs and surrounding areas with fast, reliable service. Request a free quote today and get your office on a shredding schedule that keeps you protected year-round.

Ready to get started? Contact New York Shredding for a free quote, or explore our full range of shredding services.

Scroll to Top