top of page

GLBA and PCI Compliance for Financial Sector IT Asset Disposal

  • Writer: Waqas Chaudhry
    Waqas Chaudhry
  • Aug 12
  • 8 min read

Whether a credit union is retiring a thirty-branch workstation or a regional bank is decommissioning its old servers, in both cases there are devices or hardware walking out the door containing sensitive information such as account numbers, transaction histories, and cardholder data. Just because you delete a file, close an account, or stop using the device doesn't mean it is permanently removed. 

Therefore, the gap between when a device stops being used and when it is actually destroyed is where a financial institution is subjected to two different federal laws, which include GLBA compliance for customer financial information and PCI compliance requirements for anything that touched a card transaction.

Many organizations treat them separately, but they still have to follow both of the standards when they are dealing with old equipment from financial sectors. It is best to follow the destruction process that satisfies the stricter of both. This guide provides every detail of what GLBA and PCI DSS actually require, where they overlap, and what documentation is required when a qualified security assessor audits your facility.


GLBA and PCI Compliance for Financial Sector IT Asset Disposal

Why Financial IT Asset Disposal Answers to Two Regulators at Once

Whether it is banks, credit unions, mortgage lenders, or any business that processes card payments, all are required to fulfill both consumer-protection law and payment-industry contract requirements. To differentiate, here is a clear understanding of which authorities manage both standards.

  • GLBA is a federal law enforced by the FTC and prudential banking regulators

  • PCI DSS is not a law but a contractual security standard that is set by the payment card brands through the PCI Security Standards Council. This standard is applied to anyone who stores, processes, or transmits cardholder data, no matter which size the company is.

As both these frameworks are established by different authorities, they don't automatically reference each other. It depends on what type of data a device carries.

For example, if a hard drive from a loan office holds non-public personal information, only the GLBA is applied to it, but if a drive from a payment terminal holds cardholder data, it is covered only by PCI DSS.

Similarly, a core banking server often holds both, so you need to establish both standard requirements at once, and if you are in doubt, follow the stricter one from both. 

The disposal program has to identify which device carries which type of information and then destroy each according to the standard that governs it.

What is GLBA Compliance? The Safeguards Rule and Disposal

The GLBA—Gramm-Leach-Bliley Act—is also known as the Financial Services Modernization Act of 1999. It is a federal law that requires financial institutions to protect the privacy and security of consumers' non-public personal information (NPI).

It applies to any organization that the FTC defines as a financial institution. It is a far broader category that doesn't only include banks; it refers to credit unions, mortgage brokers, tax preparers, debt collectors, investment advisors, broker-dealers, wealth management firms, insurance agencies, auto dealers that arrange financing—in short, any business that is significantly engaged in offering financial products or services.

GLBA is built around three components that include the financial privacy rule, the safeguard rule, and the pretexting provisions, but among them, the operative piece for equipment disposal is the GLBA safeguard rule. It requires an institution to develop a written information security program that covers the administrative, technical, and physical safeguards it takes to protect customer information.

The disposal rules were implicit in these requirements, but the 2023 amendments made it explicit. The following two changes matter most for ITAD programs. 

  • A documented disposal policy is now required. Institutions that relied on informal "wipe it and recycle it" habits need a written policy covering both paper records and electronic media.

  • Third-party vendor oversight is now a named obligation. If an outside company handles destruction, the institution must be able to show it selected and monitored that vendor—through a signed agreement and ideally an annual review of the vendor's process and insurance.

As the GLBA protects non-public information that includes account numbers, balances, Social Security numbers, credit applications, or anything that a customer has provided in order to get that specific financial product or service. So any device, from a workstation to a backup tape in a storage closet, falls into the disposal requirement.

What is GLBA Compliance

PCI DSS Compliance: What It Requires for Media Destruction?

Unlike GLBA, which is broad and principle-based, PCI-DSS is specific. It is founded by major card brands such as Visa, Mastercard, American Express, and Discover, and it applies to any organization that processes cardholder or sensitive authentication data, including card number, expiration data, cardholder name, etc.

PCI DSS requirements for media and hardware disposal

The current version of the standard—PCI DSS v4.0.1—addresses disposal directly under requirement 9. It restricts physical access to cardholder data and defines specifications in its subsections. Which are

  • Requirement 9.4.5—Organizations must maintain an inventory of media that stores cardholder data.

  • Requirement 9.4.6—Hard-copy materials must be destroyed such that cardholder data cannot be reconstructed (cross-cut shredding, incineration, or pulping).

  • Requirement 9.4.7—Electronic media must be destroyed or rendered unrecoverable such that cardholder data cannot be reconstructed, either through secure wiping that meets accepted industry standards or through physical destruction like shredding or degaussing.

Moreover, the practical consequences are stricter than what GLBA specifies. For hard drives and solid-state drives that store cardholder data, software wiping alone is not sufficient, especially in solid-state drives where an overwriting pass cannot guarantee that it reached every memory cell. Thus, physical destruction, i.e., shredding to a defined particle size, is considered to be the most efficient method that satisfies auditor reviews and standard requirements. Moreover, both PCI-DSS and GLBA reference NIST 800-88 as an acceptable technical standard for sanitization and apply it in their programs.

PCI DSS Compliance What It Requires for Media Destruction

Where GLBA and PCI DSS Overlap—and Where They Differ?

The two frameworks have many similarities and cover some of the same requirements, but they are not exactly the same. The table below explains the key differences between them.

Question

GLBA Safeguards Rule

PCI DSS v4.0.1

Legal status

Federal law, 

FTC-enforced

Contractual industry standard,

Card-brand enforced

Data covered

Nonpublic personal information (NPI)

Cardholder data and sensitive authentication data

Disposal method specified?

No specific method; must prevent unauthorized access

References NIST 800-88; physical destruction expected for high-sensitivity media

Vendor oversight requirement

Explicit since 2023 amendments (§314.4(f)(2))

Expected as part of the broader security program, verified during the QSA assessment

Who it applies to

Any FTC-defined financial institution

Any entity handling card transactions, regardless of sector

Documentation reviewed by

FTC / prudential regulators (OCC, FDIC, NCUA)

Qualified Security Assessor (QSA) or internal PCI compliance team

To be clear, these two frameworks can apply to the same equipment because some devices, such as a bank's core server, a branch's point of sale terminal, or an ATM, often hold both NPI and cardholder information. That’s why, instead of developing destruction processes for both standards separately, you can use a physical-destruction standard for anything that might hold cardholder data and a documented NIST 800-88 process for everything else. This makes the process easier and helps you comply with both standards efficiently. 

Destruction Methods That Satisfy Both Standards

First, understand which devices carry the risk. Obviously, the most common are workstations and servers, but the list of equipment that holds NPI or cardholder data is extensive. They may include

  • Point-of-sale terminals and payment gateways

  • ATM terminals, core banking, loan origination, and portfolio management servers

  • Backup tapes and disaster-recovery media 

  • Network hardware

  • Multifunction printers and scanners

  • Mobile devices issued to loan officers or advisers

As these frameworks reference NIST 800-88 as the sanitization standard, it is best to follow the regulations that NIST defines. It explains three sanitization levels—Clear, Purge, and Destroy—and the choice depends on which type of device you are handling or how sensitive the data is.

  • Hard disk drives (HDDs): Purge-level overwriting is acceptable for drives being redeployed internally after NPI has been removed. For drives leaving the institution's control, industrial shredding to a small particle size meets the Destroy level and gives examiners the clearest evidence of compliance.

  • Solid-state drives (SSDs): Physical shredding is the standard. Degaussing has no effect on flash memory, and overwrite tools cannot reliably reach every cell due to wear-leveling and overprovisioning.  

  • Backup tapes: Degaussing followed by physical shredding. Degaussing scrambles the magnetic domains, and shredding provides physical destruction, ensuring data erasure.

  • ATM and POS internal storage: A factory reset is not sufficient. The storage component should be physically removed and destroyed, or the entire unit processed through certified destruction.

  • Network equipment: Factory reset plus configuration verification for low-risk devices; physical destruction of internal flash storage for devices that carried cardholder or customer data traffic.

Destruction Methods for sensititve data

Documentation Examiners and QSAs Actually Ask For

Even though a bank examiner reviewing GLBA compliance and a QSA reviewing psa dss are checking against different rules, they both want to see the same core evidence to verify whether they are safely destroyed or not. These documents include

  • Serialized certificates of destruction that is issued per device with serial number, destruction method, date, and facility.  

  • Chain of custody records that are signed at every step, documenting every device from collection to destruction with no gap in custody or accountability.

  • Vendor due diligence should be completed, including the service agreement, vendor's insurance certificate, and evidence of an annual review. These documentations satisfy GLBA's third-party oversight requirements.

  • Erasure verification logs for devices where wiping is used instead of physical destruction for data destruction. 

  • Asset inventory reconciliation, which confirms that every device retired is accounted for at every step from pickup to destruction to certification.

Where Financial Institutions Most Often Get This Wrong?

A few failure patterns show up repeatedly, regardless of institution size:

  • Branch closures: When a branch closes, equipment may be moved out without proper tracking or disposal records.

  • Backup tapes: Old backup tapes can easily be overlooked and left in storage even after the servers are gone.

  • POS and ATM hardware: POS and ATM devices may end up with regular recyclers without confirming that their stored data was destroyed.

  • Vendor records: Companies sometimes lack signed vendor agreements, insurance documents, or records of regular vendor checks.

These common mistakes lead financial institutions to serious legal issues and cause severe reputational damage if a data breach occurs.

Consequences of getting it wrong

Non-compliance under each framework comes with serious consequences. Such as

Under GLBA, the FTC can take enforcement action and impose civil penalties when an institution fails to protect sensitive information. If a breach is linked to poorly disposed hardware, that can also support a Safeguards Rule violation.

Under PCI DSS, penalties come from card brands and acquiring banks rather than the government. Non-compliant businesses may face contractual fines, higher-risk status, or, in serious cases, lose the ability to accept card payments. A breach can add major costs for forensic investigations, fines, customer notification, credit monitoring, and reputational damage.

Choosing a Vendor for GLBA and PCI-Aligned Destruction

Before selecting a vendor to handle your devices and sensitive information in them, especially if your business handles financial services, you should check specific things and ensure that they handle equipment responsibly and safely and comply with both GLBA and PCI DSS requirements. These include

  • Certificates of destruction are issued per device, with serial numbers, not by batch

  • The vendor can execute a written service agreement that addresses GLBA's third-party oversight language

  • Destruction methods are mapped to NIST SP 800-88 for each media type, with physical destruction available for cardholder-data-bearing drives

  • Chain-of-custody documentation is provided from the point of pickup, not just at final destruction

  • The vendor can accommodate a records-retention hold, excluding a device from destruction if it's still subject to a legal or regulatory retention period

Atlanta eWaste Solutions: Data Destruction for Financial Institutions in Georgia

At Atlanta eWaste Solutions, we provide electronics recycling and data destruction for businesses across Atlanta and North Georgia.

For banks, credit unions, and financial services firms in the region navigating a GLBA- or PCI-driven equipment refresh, that means building the disposal process around the same core requirements covered above: destruction methods matched to the media type and its NIST SP 800-88 sanitization level, and documentation your compliance team can hand to an examiner or QSA without gaps.


 
 
 

Comments


bottom of page