Skip to main content
Advisor AtlasLeads

Your data security obligations

Page lives at advisoratlasleads.com/data-security-obligations. Surfaced during advisor onboarding at step 7 and accessible from the advisor account dashboard. v1 draft prepared 2026-06-02. AAL voice, slightly more direct given the regulatory subject matter. Em dashes hard-banned.


Your data security obligations

You are about to buy a lead. The contact information attached to that lead is regulated nonpublic personal information under federal law and is subject to several layered state privacy regimes. This page summarizes what those obligations are so you walk in with eyes open. Read it once now and again before you make your first purchase.

GLBA Safeguards Rule applies to you

The federal Gramm-Leach-Bliley Act Safeguards Rule (16 C.F.R. Part 314) treats you as a financial institution the moment you collect nonpublic personal information from a consumer in connection with a financial product. Buying a lead from Advisor Atlas Leads is exactly that.

The Rule requires you to maintain a written information security program, designate a qualified individual to oversee it, conduct a documented risk assessment, implement administrative, technical, and physical safeguards proportional to your operation, monitor and test those safeguards, train your staff, and oversee any vendors who touch the data.

Solo producers are not exempt. The Rule scales to the size and complexity of your operation; the minimum floor still applies.

State privacy laws follow the consumer

If the consumer attached to the lead lives in California, Colorado, Connecticut, Utah, Virginia, Texas, Oregon, or any other state that has passed a comprehensive privacy statute, that law follows the data. The most common obligations are to honor consumer access requests, deletion requests, opt-out requests, and to provide a clear privacy notice on your own marketing surfaces. Some states require formal contracts when you share the data with a service provider (a CRM, a marketing tool, a virtual assistant). We hold you to the Advisor Atlas Leads contractual standard in every state.

Breach notification, seventy-two hours

If you experience a data security incident affecting any consumer information you received from us, you notify us within seventy-two hours of discovery. Notification goes to security@advisoratlasleads.com and includes the timeline, the categories of data affected, the count of consumers impacted, the cause if known, and the containment status.

We coordinate with you on consumer notification if one is required by state breach notification statutes. All fifty states plus DC have one.

Retention

You may retain consumer information for as long as you maintain an active engagement with that consumer plus any record retention period required by your licensing authority. For most state insurance regulators that period is three to seven years after the engagement ends. When the retention period ends, you delete the information using a method appropriate to the medium and you log the deletion.

You do not resell, transfer, or share the consumer information with any party other than as permitted by GLBA and by the consent the consumer gave at the original source. This includes lead resale networks, data brokers, IMOs other than the one named at purchase, and any AI tool that retains training data.

What Advisor Atlas Leads contractually requires

Section 10 of the Advisor Marketplace Agreement binds you to the obligations above and adds three operational requirements. Encryption at rest and in transit for any stored consumer data. Multi-factor authentication on every account that can access consumer data, including any CRM, email platform, or shared drive. An annual self-attestation that your written information security program is current and that you have reviewed it within the past twelve months.

If something goes wrong

A confirmed material breach is grounds for immediate account suspension, forfeiture of any unused wallet balance under Section 22 of the Agreement, and reporting to the relevant state insurance regulator if licensure conditions or NAIC model regulations require it. We do not negotiate this. The consumer's trust is the asset we are protecting, including from our own marketplace.

If you are not sure whether something is a breach, treat it as one and call us. Better to overreport.

Where to read more

Advisor Marketplace Agreement, Section 10 (data security and confidentiality): /terms-of-service.

GLBA Safeguards Rule, official FTC compliance guide: ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know.

NAIC Insurance Data Security Model Law (as adopted in your state).

State privacy law summary by jurisdiction: maintained at /data-security-obligations/state-summary.

Questions: security@advisoratlasleads.com.


Surfaced during advisor onboarding at step 7. Acknowledgment of viewing is logged to the advisor eligibility log. Annual self-attestation reminder fires twelve months after first acknowledgment.